Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Red Hat JBoss Application Server Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability exists in JBoss Application Server versions included with Red Hat Enterprise Application Platform 5.2. The issue arises because the 'doFilter' method in the 'ReadOnlyAccessFilter' of the HTTP Invoker does not properly restrict which classes can be deserialized. This flaw allows attackers to execute arbitrary code by sending crafted serialized data. The vulnerability is known to be exploited in ransomware campaigns.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where JBoss Application Server is running.

Reproduction

To reproduce this vulnerability, deploy an application on JBoss Application Server 5.2 that uses the HTTP Invoker. The vulnerability can be triggered by sending serialized data that exploits the deserialization process in the 'ReadOnlyAccessFilter', allowing arbitrary code to be executed on the server.

Remediation

Users can update to the latest version of Red Hat JBoss Enterprise Application Platform 5.2.0, where this vulnerability has been addressed. Instructions for applying the update are available on the Red Hat JBoss Enterprise Application Platform documentation page.

Added: May 15, 2026, 10:50 AM
Updated: May 15, 2026, 10:50 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
7.5
exploitability
9.2
remediation
8.3
relevance
0.0
threat
9.9
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.