PT-2026-24898 · Alfresco · Activiti
Ana10Gy
+1
·
Published
2026-03-12
·
Updated
2026-03-12
·
CVE-2026-3967
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Alfresco Activiti versions prior to 7.19/8.8.0
Description
An issue exists in Alfresco Activiti related to the Process Variable Serialization System component. Specifically, the
deserialize/createObjectInputStream function within the SerializableType.java file (located at activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java) is susceptible to deserialization manipulation. Remote exploitation is possible. The exploit for this issue has been published. The vendor was contacted regarding this disclosure but did not respond.Recommendations
Update Alfresco Activiti to a version prior to 7.19/8.8.0.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Activiti