Executive brief
Infinispan, a distributed caching system used in enterprise Java applications, contains a flaw in its session replication mechanism that allows remote code execution. The vulnerability bypasses security controls during deserialization of session data transmitted between cluster nodes, enabling an attacker with network access to execute arbitrary code on every server in the cluster.
Technical details
This is a deserialization vulnerability in the Infinispan session replication path. The JBoss Marshalling River unmarshaller deserializes replicated session data without class filtering, permitting exploitation via gadget chains. An attacker with network access to the Infinispan cluster can craft malicious serialized objects that, when deserialized, execute arbitrary code on cluster nodes. The vulnerability affects the inter-node communication channel and requires no authentication or user interaction. Patches addressing class filtering or alternative serialization mechanisms are expected from Red Hat.
Affected products
- Red Hat Infinispan <UNKNOWN>
Timeline
- 2026-08-11: disclosed