Junglewise Threat Intelligence

CVE-2026-52439: xiandafu Beetl remote code execution via type.new and reflection

CVE-2026-52439 · Severity: info · CVSS 9.8 · Published 2026-07-23

Executive brief

Beetl is a high-performance Java template engine used to generate dynamic web pages and code. A security vulnerability allows remote attackers to bypass safety restrictions and execute arbitrary code on the server. This could lead to a full system takeover, data theft, or unauthorized access to internal resources.

Technical details

A remote code execution (RCE) vulnerability exists in Beetl <= 3.20.2 due to an Expression Language (EL) injection flaw (CWE-917). Even when the 'NATIVE_CALL' security setting is set to false, the 'type.new' function allows for the instantiation of arbitrary Java classes. Attackers can chain this with Beetl's property reflection mechanism, which implicitly calls setter and getter methods via Java introspection. By instantiating sensitive classes (such as JdbcRowSetImpl or BCEL ClassLoaders) and manipulating their properties, an attacker can achieve RCE via JNDI injection or malicious bytecode loading. The vulnerability is reachable if the application renders user-supplied template content.

Affected products

  • xiandafu Beetl <= 3.20.2

Timeline

  • 2026-05-18: disclosed: Issue reported on Gitee repository
  • 2026-07-23: advisory: CVE published to NVD

References

Related threats