Description
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component

 in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat

 (only when Tribes clustering is enabled, which is off by default) allows an

 unauthenticated remote attacker with network access to the clustering port to

 execute arbitrary code via a crafted serialized Java object delivered to the cluster

 channel and deserialized in

 org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are

 recommended to upgrade to version 2.0.1, which fixes this issue by removing the

 clustering feature entirely.
Published: 2026-07-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat  (only when Tribes clustering is enabled, which is off by default) allows an  unauthenticated remote attacker with network access to the clustering port to  execute arbitrary code via a crafted serialized Java object delivered to the cluster  channel and deserialized in  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are  recommended to upgrade to version 2.0.1, which fixes this issue by removing the  clustering feature entirely.
Title Apache Axis2/Java: deserialization of untrusted Data
Weaknesses CWE-502
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-28T14:53:41.497Z

Reserved: 2026-07-27T14:49:00.907Z

Link: CVE-2026-66713

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses