Junglewise Threat Intelligence

CVE-2026-67615: openEQUELLA remote code execution via Java deserialization

CVE-2026-67615 · Severity: high · CVSS 8.8 · Published 2026-09-22

Executive brief

openEQUELLA is a digital repository system used by universities to store and manage media content. Any authenticated user can execute arbitrary code on the server by sending a crafted serialized Java object to the HTTP invoker endpoint. This allows an attacker with a valid account to take complete control of the system and access all stored data.

Technical details

The vulnerability exists in the /invoker/* endpoint which deserializes untrusted Java objects without proper validation. Attackers bypass the PluginAwareObjectInputStream class-name denylist by wrapping a malicious payload in a java.security.SignedObject, causing the inner payload to be deserialized by a separate ObjectInputStream that does not enforce the denylist. The attacker can then chain gadgets to reach a JNDI sink, achieving remote code execution through LDAP callback injection.

Affected products

  • openEQUELLA openEQUELLA before 2026.1.0

Timeline

  • 2026-09-22: disclosed: CVE-2026-67615 published
  • 2026-09-04: patched: Fixed in version 2026.1.0

References

Related threats