Codelibs Fess Remote Code Execution Vulnerability via Admin Design Action

Vulnerability

A code injection vulnerability allowing remote code execution has been identified in Codelibs Fess versions through 15.5.1. The issue arises in the JSP File Handler component, specifically within the update function of the AdminDesignAction.java file. The vulnerability is exploited by manipulating the content argument, which leads to arbitrary code execution on the server.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where Fess is running.

Reproduction

To reproduce this vulnerability, upload a malicious JSP file through the Admin Design Action. Once the file is uploaded, access it via the web application and append a command parameter to execute arbitrary commands on the server. The output will be displayed at the bottom of the page.

Added: May 9, 2026, 11:18 PM
Updated: May 9, 2026, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
7.5
exploitability
8.9
remediation
0.0
relevance
7.8
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.