Junglewise Threat Intelligence

CVE-2026-71374: Hitachi Cosminexus Component Container deserialization of untrusted data

CVE-2026-71374 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Technologies: Hitachi Cosminexus Component Container. Vendors: Hitachi.

Executive brief

Cosminexus Component Container is a core component of Hitachi's enterprise application server and middleware products. An insecure deserialization vulnerability allows remote attackers to execute arbitrary code without authentication, potentially compromising the entire application server and any sensitive business data it processes. This could lead to complete system compromise, data theft, or service disruption across dependent business applications.

Technical details

The vulnerability is an insecure deserialization flaw in Cosminexus Component Container that allows attackers to deserialize untrusted data. The issue affects multiple versions across Cosminexus V9 and V11 product lines. The vulnerability is remotely exploitable over the network with no authentication required (CVSS vector AV:N/AC:L/PR:N/UI:N), and can result in complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Hitachi has released fixed versions including Cosminexus Component Container 09-70-28, 09-87-10, 11-00-13, 11-20-10, 11-60-03, and 11-70-03 across supported platforms. Organizations using affected versions should upgrade immediately.

Affected products

  • Hitachi Cosminexus Component Container V9 and V11 versions; specific affected ranges include 09-00 through 09-87, 11-00 through 11-70
  • Hitachi uCosminexus Developer V9 and V11
  • Hitachi uCosminexus Application Server V9 and V11
  • Hitachi uCosminexus Application Server-R V9 and V11
  • Hitachi uCosminexus Service Platform V9 and V11
  • Hitachi uCosminexus Service Architect V9 and V11
  • Hitachi uCosminexus Primary Server Base V9 and V11

Timeline

  • 2026-09-08: disclosed: Vulnerability details and advisory published

References

Related threats