Description
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component

 in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat

 (only when Tribes clustering is enabled, which is off by default) allows an

 unauthenticated remote attacker with network access to the clustering port to

 execute arbitrary code via a crafted serialized Java object delivered to the cluster

 channel and deserialized in

 org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are

 recommended to upgrade to version 2.0.1, which fixes this issue by removing the

 clustering feature entirely.
Published: 2026-07-28
Score: 9.8 Critical
EPSS: 1.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Axis2/java
Vendors & Products Apache
Apache apache Axis2/java

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are  recommended to upgrade to version 2.0.1, which fixes this issue by removing the  clustering feature entirely.
Title Apache Axis2/Java: deserialization of untrusted Data
Weaknesses CWE-502
References

Subscriptions

Apache Apache Axis2/java Axis2\/java
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-29T03:55:41.433Z

Reserved: 2026-07-27T14:49:00.907Z

Link: CVE-2026-66713

cve-icon Vulnrichment

Updated: 2026-07-28T14:53:41.497Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-28T15:17:50.430

Modified: 2026-08-05T18:45:24.883

Link: CVE-2026-66713

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-28T13:44:29Z

Links: CVE-2026-66713 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T09:15:03Z

Weaknesses