{"id":"CVE-2026-94109","published":"2026-09-20T12:17:06.620","lastModified":"2026-09-24T12:17:13.817","description":"openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. The markup field from stored portlet configuration is passed directly to custFactory.createResult() without a TemplateClassResolver restriction or FreeMarker sandboxing in BasicConfiguration, leaving built-ins such as ?new and freemarker.template.utility.Execute available, causing the payload to execute in the application server process context when any user renders a dashboard containing the affected portlet.","cvssScore":8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-1336"],"vendors":[],"products":[],"references":[{"url":"https://blog.evan.lat/posts/openeq","tags":[]},{"url":"https://github.com/openequella/openEQUELLA/commit/d6e165afc986f8a3ed912cdb367d5ad8c1eeab5c","tags":[]},{"url":"https://github.com/openequella/openEQUELLA/releases/tag/2026.1.0","tags":[]},{"url":"https://www.vulncheck.com/advisories/openequella-authenticated-stored-ssti-via-freemarkerportletrenderer","tags":[]}],"exploitRefs":[{"url":"https://github.com/openequella/openEQUELLA/commit/d6e165afc986f8a3ed912cdb367d5ad8c1eeab5c","tags":[]},{"url":"https://github.com/openequella/openEQUELLA/releases/tag/2026.1.0","tags":[]}],"hasPoc":true,"ai":null}