THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-40858 (HIGH 8.8) — The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel applica

[NVD] CVE-2026-40858 (HIGH 8.8) — The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel applica

lownvdPublished 2026-04-27

CVE-2026-40858 CVSS: 8.8 HIGH Published: 2026-04-27T10:16:09.627

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40858