CVE-2026-27727
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted `jaxax.naming.Reference` or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the JDK were disabled by default behind a System property that defaults to `false`, `com.sun.jndi.ldap.object.trustURLCodebase`. However, since mchange-commons-java includes an independent implementation of JNDI derefencing, libraries (such as c3p0) that resolve references via that implementation could be provoked to download and execute malicious code even after the JDK was hardened. Mirroring the JDK patch, mchange-commons-java's JNDI functionality is gated by configuration parameters that default to restrictive values starting in version 0.4.0. No known workarounds are available. Versions prior to 0.4.0 should be avoided on application CLASSPATHs.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.81%
- CWE
- CWE-74
- Published
- 2026-02-25
- Last modified
- 2026-09-15
Affected products
- swaldman mchange-commons-java
Weakness type
Related vulnerabilities
- CVE-2026-87572 — Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer
- CVE-2026-82971 — QVidium Opera11 CGI Script net_tr.cgi command injection
- CVE-2026-20130 — Cisco Identity Services Engine Hardening Release - Improper Neutralization Vulnerabilities
- CVE-2026-12351 — IBM MQ is vulnerable to unauthenticated remote code execution via JNDI injection
- CVE-2026-79697 — Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
- CVE-2026-79698 — Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
- CVE-2026-79234 — Injection in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially obtain sensitive infor
- CVE-2026-83772 — Cobham SATCOM VSAT7090 Maritime Satellite Router JSON Parsing mail-report.sh c_set_reports_decode command injection