Description
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Fix
AI Analysis

Impact

The flaw is an insecure deserialization vulnerability in the MailReceiver component of lenve vhr 1.0-SNAPSHOT, allowing an attacker to send crafted input that is deserialized without proper validation. This can lead to arbitrary code execution or other malicious actions on the host. The weakness is a classic unserialization flaw (CWE-502) coupled with insufficient input validation (CWE-20).

Affected Systems

Lenve VHR 1.0-SNAPSHOT is affected by this issue. The security flaw specifically lies within the MailReceiver component of the product.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity, but the public release of an exploit and the ability to attack remotely raise concerns. EPSS is <1%, indicating a very low yet nonzero exploitation probability, though the existence of a published exploit implies a realistic threat. This vulnerability is not listed in CISA's KEV catalog, but the remote nature of the attack and the lack of vendor response suggest it could serve as a foothold for further compromise.

Generated by OpenCVE AI on September 15, 2026 at 17:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a patched version of lenve vhr once it becomes available.
  • Restrict or disable the MailReceiver service if it is not needed for business operations.
  • Apply input validation or switch to a safer deserialization approach to ensure only trusted data is processed.

Generated by OpenCVE AI on September 15, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title lenve vhr MailReceiver deserialization
First Time appeared Lenve
Lenve vhr
Weaknesses CWE-20
CWE-502
CPEs cpe:2.3:a:lenve:vhr:*:*:*:*:*:*:*:*
Vendors & Products Lenve
Lenve vhr
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T18:15:49.280Z

Reserved: 2026-09-12T08:03:40.929Z

Link: CVE-2026-90490

cve-icon Vulnrichment

Updated: 2026-09-14T18:14:46.226Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T01:16:37.520

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-502

    Deserialization of Untrusted Data