Executive brief
openEQUELLA is a digital repository system used by universities to store and manage media content. Any authenticated user can execute arbitrary code on the server by sending a crafted serialized Java object to the HTTP invoker endpoint. This allows an attacker with a valid account to take complete control of the system and access all stored data.
Technical details
The vulnerability exists in the /invoker/* endpoint which deserializes untrusted Java objects without proper validation. Attackers bypass the PluginAwareObjectInputStream class-name denylist by wrapping a malicious payload in a java.security.SignedObject, causing the inner payload to be deserialized by a separate ObjectInputStream that does not enforce the denylist. The attacker can then chain gadgets to reach a JNDI sink, achieving remote code execution through LDAP callback injection.
Affected products
- openEQUELLA openEQUELLA before 2026.1.0
Timeline
- 2026-09-22: disclosed: CVE-2026-67615 published
- 2026-09-04: patched: Fixed in version 2026.1.0