Description
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive jmx.remote.rmi.server.credentials.filter.pattern, and RmiAuthenticator.authenticate in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiAuthenticator.java accepts an unconstrained Object array rather than a two-element String[]. When the JMX Connection Handler is enabled and its TCP listener is reachable, an unauthenticated remote attacker can submit a crafted serialized Java object and achieve code execution in the OpenDJ server process. The handler is disabled by default, and successful exploitation depends on the runtime classpath and Java version; remote code execution was demonstrated against OpenDJ 4.4.15 on JDK 11 with Jackson 2.12.6.1. This issue is fixed in 5.1.1.
Published: 2026-09-15
Score: 9.2 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

OpenDJ versions before 5.1.1 contain a flaw in the JMX RMI connector that processes attacker‑controlled credential objects before authentication. Because the connector does not enforce a restrictive credential filter and the authentication routine accepts an unconstrained Object array, an unauthenticated attacker can craft a serialized Java object and have it deserialized by the server. Delivering the payload to the open TCP listener for the JMX Connection Handler—enabled by default only in the legacy module—allows the attacker to execute arbitrary code in the OpenDJ process. The vulnerability depends on the runtime classpath and the Java runtime; code‑execution was shown on OpenDJ 4.4.15 running JDK 11 with Jackson 2.12.6.1. This flaw is a Java deserialization vulnerability (CWE‑502).

Affected Systems

The affected products are OpenIdentityPlatform OpenDJ and the opendj-server-legacy module, for all releases older than 5.1.1, including the 4.4.15 build that was successfully exploited. The JMX Connection Handler is disabled by default but must be enabled to be vulnerable.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity, and the EPSS score is less than 1%, suggesting limited current exploitation activity. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network visibility to the JMX RMI service; the TCP listener must be reachable and the JMX Connection Handler enabled. Once accessed, the attacker can send a crafted object to trigger deserialization and gain full code execution in the OpenDJ server process, with no authentication required. The risk remains high due to the critical CVSS rating and the potential for remote code execution.

Generated by OpenCVE AI on September 17, 2026 at 15:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to OpenDJ 5.1.1 or later to apply the vendor patch.
  • If an upgrade is not immediately possible, disable the JMX RMI connector or close its TCP listener to prevent remote access.
  • Restrict firewall rules to allow the JMX RMI port only from trusted hosts.
  • Verify that the OpenDJ service runs with the minimum required Java version and remove unused libraries such as legacy Jackson implementations.

Generated by OpenCVE AI on September 17, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-43x2-g84q-fmqx OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Openidentityplatform
Openidentityplatform opendj
Vendors & Products Openidentityplatform
Openidentityplatform opendj

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive jmx.remote.rmi.server.credentials.filter.pattern, and RmiAuthenticator.authenticate in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiAuthenticator.java accepts an unconstrained Object array rather than a two-element String[]. When the JMX Connection Handler is enabled and its TCP listener is reachable, an unauthenticated remote attacker can submit a crafted serialized Java object and achieve code execution in the OpenDJ server process. The handler is disabled by default, and successful exploitation depends on the runtime classpath and Java version; remote code execution was demonstrated against OpenDJ 4.4.15 on JDK 11 with Jackson 2.12.6.1. This issue is fixed in 5.1.1.
Title OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Openidentityplatform Opendj
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:48:13.800Z

Reserved: 2026-05-14T18:06:06.811Z

Link: CVE-2026-46495

cve-icon Vulnrichment

Updated: 2026-09-15T14:48:08.596Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:15.493

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-46495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:59:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data