High severity7.5NVD Advisory· Published Aug 5, 2026· Updated Aug 10, 2026
CVE-2026-46581
CVE-2026-46581
Description
In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*range: >=2.3.0,<=4.1.13
- cpe:2.3:a:eclipse:mojarra:5.0.0:milestone1:*:*:*:*:*:*
- cpe:2.3:a:eclipse:mojarra:5.0.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:eclipse:mojarra:5.0.0:milestone3:*:*:*:*:*:*
- cpe:2.3:a:eclipse:mojarra:5.0.0:milestone4:*:*:*:*:*:*
- cpe:2.3:a:eclipse:mojarra:5.0.0:milestone5:*:*:*:*:*:*
- (no CPE)range: >=2.3
Patches
Vulnerability mechanics
References
2- gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544nvdExploitVendor Advisory
- gitlab.eclipse.org/security/cve-assignment/-/work_items/160nvdVendor Advisory
News mentions
0No linked articles in our index yet.