Critical severityGHSA Advisory· Published May 7, 2026· Updated May 7, 2026
CVE-2026-41586
CVE-2026-41586
Description
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.hyperledger.fabric-sdk-java:fabric-sdk-javaMaven | >= 1.0.0, <= 2.2.26 | — |
Affected products
1- Range: >= 1.0.0, <= 2.2.26
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
11- Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)Help Net Security · May 15, 2026
- Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)Tenable Blog · May 15, 2026
- Bring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assetsTenable Blog · May 14, 2026
- CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)Rapid7 Blog · May 14, 2026
- SailPoint Agentic Fabric expands identity governance to autonomous AI agentsHelp Net Security · May 11, 2026
- ServiceNow clears agents for landing with new AI control towerThe Register Security · May 5, 2026
- Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AITenable Blog · May 1, 2026
- New infosec products of the month: April 2026Help Net Security · May 1, 2026
- Hypersonic Supply Chain Attacks: One Solution That Didn’t Need to Know the PayloadSentinelOne Labs · Apr 22, 2026
- Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patchingTenable Blog · Apr 16, 2026
- Building the foundation for running extra-large language modelsCloudflare Blog · Apr 16, 2026