THREATOPS
THREAT OPSThreat News › Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)

Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)

lowfulldisclosurePublished 2026-08-18

<p>Posted by disclosure via Fulldisclosure on Aug 17</p>0day Rubbish Research Team is publicly disclosing a vulnerability in ObjectDB 2.9.5 server mode (ObjectDB Software). <br /> The research is published and a proof-of-concept is available.<br /> <br /> Pre-authentication RCE (default credentials) (CVSS 9.8, pre-authentication)<br /> <br /> ObjectDB 2.9.5 server mode (port 6136, proprietary bina

MITRE ATT&CK techniques

Original source: https://seclists.org/fulldisclosure/2026/Aug/58