{"id":"CVE-2026-94301","published":"2026-09-21T15:17:38.903","lastModified":"2026-09-22T04:18:02.810","description":"The fix for CVE-2026-47065/ZDRES-232 (\"resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\"), released on 2026-06-02 and announced as \"Fully addressed\" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the\n 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/rzos6zds5x7obl8trkvznt1djw4f996p","tags":[]},{"url":"https://lists.apache.org/thread/x4667tn5ozbvkc3wz87lhzogbfl0dczj","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows for an allow-list bypass via java.lang.reflect.Proxy, enabling unauthorized access. It matters because it can lead to remote code execution or data leakage.","exploitability":"Exploitation is moderately hard as it requires specific conditions and knowledge of the affected versions. Precondition is the use of vulnerable versions of MINA 2.0.X and 2.1.X.","blast_radius":"If exploited, this could result in unauthorized access, data theft, or remote code execution across affected systems.","remediation":"Upgrade to MINA 2.0.30 or later, and 2.1.14 or later, to address the vulnerability.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web","java"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:59:59.893Z"}}