Executive brief
Lenve VHR is an HR management application that processes email through a mail receiver component. An attacker can remotely send a malicious serialized Java object via RabbitMQ that triggers arbitrary code execution when deserialized, potentially compromising the entire application and associated data without requiring authentication.
Technical details
This is a Java deserialization vulnerability in the MailReceiver component of Lenve VHR 1.0-SNAPSHOT. The vulnerability occurs when untrusted serialized Java objects are deserialized without proper validation, allowing an attacker to craft malicious payloads using gadget chains (e.g., Apache Commons Collections) to achieve remote code execution. The attack is delivered remotely via RabbitMQ message queue to the javaboy.mail.queue queue. No authentication is required if the RabbitMQ service is accessible or uses default credentials (guest:guest). The exploit is publicly available and has been released. A proof-of-concept demonstrates successful command execution on the target system. The vendor did not respond to early disclosure notifications.
Affected products
- Lenve VHR 1.0-SNAPSHOT
Timeline
- 2026-09-13: disclosed: Public disclosure via GitHub advisory
- exploited: Exploit proof-of-concept publicly released