CVE-2026-27727
swaldman mchange-commons-java, Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11, Red Hat Build of Debezium 3.2
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted `jaxax.naming.Reference` or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to `false`, `com.sun.jndi.ldap...
- CVSS
- 8.9
- EPSS
- 0.81% 53.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.26