VYPR
High severity7.5NVD Advisory· Published Aug 5, 2026· Updated Aug 10, 2026

CVE-2026-46581

CVE-2026-46581

Description

In Eclipse Mojarra versions 2.3 and following, URL handing in DefaultFaceletFactory does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as WEB-INF/web.xml or /etc/passwd.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Eclipse/Mojarra7 versions
    cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*range: >=2.3.0,<=4.1.13
    • cpe:2.3:a:eclipse:mojarra:5.0.0:milestone1:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:mojarra:5.0.0:milestone2:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:mojarra:5.0.0:milestone3:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:mojarra:5.0.0:milestone4:*:*:*:*:*:*
    • cpe:2.3:a:eclipse:mojarra:5.0.0:milestone5:*:*:*:*:*:*
    • (no CPE)range: >=2.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.