CVE-2026-94109
8 HIGHpublic exploit availablePublished 2026-09-20 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. The markup field from stored portlet configuration is passed directly to custFactory.createResult() without a TemplateClassResolver restriction or FreeMarker sandboxing in BasicConfiguration, leaving built-ins such as ?new and freemarker.template.utility.Execute available, causing the payload to execute in the application server process context when any user renders a dashboard containing the affected portlet.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-1336
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-102771PoC
- HIGHCVE-2026-12370
- HIGHCVE-2026-71239PoC
- MEDIUMCVE-2026-71286PoC
- HIGHCVE-2026-71291PoC
- MEDIUMCVE-2026-73858PoC
- UNSCOREDCVE-2026-84462PoC
- HIGHCVE-2026-88064PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.