Skip to content
VulniPulse
Advisory severityHigh8.1Red Hat Linux

High [CVE-2026-66909] Remote Code Execution via unsafe deserialization of JMS ObjectMessage

This high-severity Red Hat Linux advisory covers CVE-2026-66909 affecting Red Hat build of Apache Camel for Spring Boot 4, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-66909 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place.

Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed.

Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. The Java Message Service (JMS) transport component improperly deserializes inbound JMS ObjectMessages without type restrictions.

This vulnerability could lead to a denial of service or, in certain configurations, enable remote code execution on the affected system. This vulnerability in Apache CXF's JMS transport is rated as Important because it allows for remote code execution or denial of service if an attacker can send a specially crafted JMS ObjectMessage to a service.

This is particularly relevant in Red Hat environments where Apache CXF is used in applications that process JMS messages, as the default deserialization behavior without type restrictions increases the attack surface. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Weakness: CWE-502.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 23 days ago·verify at source

Fixed versions
  • 4.2.3
  • 4.1.8
  • 3.6.12

Official advisory · high-confidence parse· fetched 23 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this vulnerability, disable ObjectMessage deserialization in Apache CXF's JMS transport. This can typically be achieved through a configuration setting provided by the Apache CXF framework. Consult the Apache CXF documentation for specific instructions on how to disable ObjectMessage deserialization in your deployment. Disabling this feature may impact applications that rely on ObjectMessage for legitimate data transfer.

Official advisory · high-confidence parse· fetched 23 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.