VYPR
Critical severity9.8NVD Advisory· Published Jul 28, 2026· Updated Aug 5, 2026

CVE-2026-66713

CVE-2026-66713

Description

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component

in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat

(only when Tribes clustering is enabled, which is off by default) allows an

unauthenticated remote attacker with network access to the clustering port to

execute arbitrary code via a crafted serialized Java object delivered to the cluster

channel and deserialized in

org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are

recommended to upgrade to version 2.0.1, which fixes this issue by removing the

clustering feature entirely.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.