cve-2026-6857

HIGH CVSS 7.5 csaf_redhat
Description

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Timeline
Published
2026-04-13 00:00 UTC
Last Modified
2026-08-26
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6857.json"
      }
    ],
    "title": "camel-infinispan: camel-infinispan: Remote Code Execution via Unsafe Deserialization",
    "tracking": {
      "current_release_date": "2026-08-26T15:46:13+00:00",
      "generator": {
        "date": "2026-08-26T15:46:13+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.16"
        }
      },
      "id": "CVE-2026-6857",
      "initial_release_date": "2026-04-13T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-04-13T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-10T11:00:52.758843+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-26T15:46:13+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel 4 for Quarkus 3",
                "product": {
                  "name": "Red Hat build of Apache Camel 4 for Quarkus 3",
                  "product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:camel_quarkus:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat build of Apache Camel 4 for Quarkus 3"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Fuse 7",
                "product": {
                  "name": "Red Hat Fuse 7",
                  "product_id": "red_hat_fuse_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_fuse:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Fuse 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 8",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 8",
                  "product_id": "red_hat_jboss_enterprise_application_platform_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
                  "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jbosseapxp"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform Expansion Pack"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
                "product": {
                  "name": "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
                  "product_id": "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:apache_camel_quarkus:3.33"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
                "product": {
                  "name": "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
                  "product_id": "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:apache_camel_spring_boot:4.18"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Build of Apache Camel"
          },
          {
            "category": "product_version",
            "name": "camel-infinispan",
            "product": {
              "name": "camel-infinispan",
              "product_id": "camel-infinispan",
              "product_identification_helper": {
                "purl": "pkg:maven/org.apache.camel/camel-infinispan"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "camel-infinispan as a component of Red Hat build of Apache Camel 4 for Quarkus 3",
          "product_id": "red_hat_build_of_apache_camel_4_for_quarkus_3:camel-infinispan"
        },
        "product_reference": "camel-infinispan",
        "relates_to_product_reference": "red_hat_build_of_apache_camel_4_for_quarkus_3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "camel-infinispan as a component of Red Hat Fuse 7",
          "product_id": "red_hat_fuse_7:camel-infinispan"
        },
        "product_reference": "camel-infinispan",
        "relates_to_product_reference": "red_hat_fuse_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "camel-infinispan as a component of Red Hat JBoss Enterprise Application Platform 8",
          "product_id": "red_hat_jboss_enterprise_application_platform_8:camel-infinispan"
        },
        "product_reference": "camel-infinispan",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "camel-infinispan as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "product_id": "red_hat_jboss_enterprise_application_platform_expansion_pack:camel-infinispan"
        },
        "product_reference": "camel-infinispan",
        "relates_to_product_reference": "red_hat_jboss_enterprise_application_platform_expansion_pack"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Feng Ning"
          ],
          "organization": "Innora Pte. Ltd."
        }
      ],
      "cve": "CVE-2026-6857",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "discovery_date": "2026-04-13T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_jboss_enterprise_application_platform_8:camel-infinispan",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:camel-infinispan"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2460003"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "camel-infinispan: camel-infinispan: Remote Code Execution via Unsafe Deserialization",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability has an Important impact on Red Hat products utilizing `camel-infinispan` for remote aggregation. The flaw stems from unsafe deserialization within the ProtoStream remote aggregation repository, which could lead to remote code execution. This affects Red Hat Enterprise Application Platform and Red Hat JBoss Fuse when configured to use `camel-infinispan`.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
          "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14"
        ],
        "known_affected": [
          "red_hat_build_of_apache_camel_4_for_quarkus_3:camel-infinispan",
          "red_hat_fuse_7:camel-infinispan"
        ],
        "known_not_affected": [
          "red_hat_jboss_enterprise_application_platform_8:camel-infinispan",
          "red_hat_jboss_enterprise_application_platform_expansion_pack:camel-infinispan"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-6857"
        },
        {
          "category": "external",
          "summary": "RHBZ#2460003",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2460003"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-6857",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-6857"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-6857",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6857"
        }
      ],
      "release_date": "2026-04-13T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-02T11:27:09+00:00",
          "details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.\nThe References section of this erratum contains a download link (you must log in to download the update).",
          "product_ids": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:22453"
        },
        {
          "category": "vendor_fix",
          "date": "2026-05-14T16:55:24+00:00",
          "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:17668"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
            "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
            "red_hat_build_of_apache_camel_4_for_quarkus_3:camel-infinispan",
            "red_hat_fuse_7:camel-infinispan"
          ]
        },
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "red_hat_fuse_7:camel-infinispan"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_build_of_apache_camel_4_for_quarkus_3:camel-infinispan"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
            "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
            "red_hat_build_of_apache_camel_4_for_quarkus_3:camel-infinispan",
            "red_hat_fuse_7:camel-infinispan",
            "red_hat_jboss_enterprise_application_platform_8:camel-infinispan",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:camel-infinispan"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "Red Hat Build of Apache Camel 4.18 for Quarkus 3.33",
            "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
            "red_hat_build_of_apache_camel_4_for_quarkus_3:camel-infinispan",
            "red_hat_fuse_7:camel-infinispan",
            "red_hat_jboss_enterprise_application_platform_8:camel-infinispan",
            "red_hat_jboss_enterprise_application_platform_expansion_pack:camel-infinispan"
          ]
        }
      ],
      "title": "camel-infinispan: camel-infinispan: Remote Code Execution via Unsafe Deserialization"
    }
  ]
}
Enrichment data
View JSON API Download JSON