when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
History

Tue, 11 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 11 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
Title Openjdk-orb: unauthed class loading via iiop in eap
First Time appeared Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Weaknesses CWE-829
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
Vendors & Products Redhat
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-11T08:49:45.288Z

Reserved: 2026-07-13T05:05:58.334Z

Link: CVE-2026-15560

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T09:17:12.823

Modified: 2026-08-11T09:17:12.823

Link: CVE-2026-15560

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T05:52:32Z

Links: CVE-2026-15560 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T10:30:04Z