Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
CVE-2026-46581
CVE-2026-46581
Description
In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.