PT-2026-24898 · Alfresco · Activiti

Ana10Gy

+1

·

Published

2026-03-12

·

Updated

2026-03-12

·

CVE-2026-3967

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Alfresco Activiti versions prior to 7.19/8.8.0
Description An issue exists in Alfresco Activiti related to the Process Variable Serialization System component. Specifically, the deserialize/createObjectInputStream function within the SerializableType.java file (located at activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java) is susceptible to deserialization manipulation. Remote exploitation is possible. The exploit for this issue has been published. The vendor was contacted regarding this disclosure but did not respond.
Recommendations Update Alfresco Activiti to a version prior to 7.19/8.8.0.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-3967

Affected Products

Activiti