Junglewise Threat Intelligence

CVE-2025-3586: Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations

CVE-2025-3586 · Severity: low · CVSS 3.1 · Published 2025-12-12

Technologies: com.liferay:com.liferay.object.service (Maven). Vendors: Maven.

Executive brief

Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations

Affected products

  • Maven com.liferay:com.liferay.object.service

Related threats