# CVE-2026-46581

## Summary

- **CVE ID:** CVE-2026-46581
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-22, CWE-94, CWE-641
- **Published:** Aug 5, 2026
- **Last Modified:** Aug 5, 2026

## Description

In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.

## Affected Products

- Eclipse Foundation — Eclipse Mojarra (2.3)

## References

- [CNA](https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544)
- [CNA](https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.44%
- **EPSS Percentile:** 36.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._