Status: UPDATED
| Advisory ID: CVE-2026-6857
Key Details
| CVE | CVE-2026-6857 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat build of Apache Camel 4 for Quarkus 3 and Red Hat Red Hat Fuse 7 |
| Classified as | CWE-502 (Deserialization of Untrusted Data) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References