# CVE-2026-41883

## Summary

- **CVE ID:** CVE-2026-41883
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-917
- **Published:** May 8, 2026
- **Last Modified:** May 8, 2026

## Description

OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example.com/*). An attacker can craft a resource request URL containing an EL expression in the resource name, which is evaluated server-side. This issue has been patched in versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3.

## Affected Products

- omnifaces — omnifaces (< 1.14.2)
- omnifaces — omnifaces (>= 2.0-RC1, < 2.7.32)
- omnifaces — omnifaces (>= 3.0-RC1, < 3.14.16)
- omnifaces — omnifaces (>= 4.0-M1, < 4.7.5)
- omnifaces — omnifaces (>= 5.0-M1, < 5.2.3)

## References

- [CNA](https://github.com/omnifaces/omnifaces/security/advisories/GHSA-vp6r-9m58-5xv8)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.50%
- **EPSS Percentile:** 40.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._