Unsafe reflection in Mchange Commons Java - CVE-2026-55153
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unsafe reflection in com.mchange.v2.naming.JavaBeanObjectFactory when processing malicious JNDI Reference objects or Java-serialized objects. A remote user can cause an application to process a malicious object to execute arbitrary code.
Known deserialization gadget chains require a JVM prior to Java 16 and affected Apache commons-beanutils and commons-collections libraries on the application classpath.
Affected software
Crucible Server
Crucible Data Center
Bamboo Data Center
How to mitigate CVE-2026-55153
Crucible Server - update to 4.9.14
Crucible Data Center - update to 4.9.14
Bamboo Data Center - addressed in versions 10.2.19, 12.1.7