Impact
The vulnerability stems from an unsandboxed TemplateClassResolver in the FreeMarker template engine. Authenticated users can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates, enabling the instantiation of dangerous classes such as freemarker.template.utility.Execute. This class can invoke Runtime.exec, allowing attackers to run arbitrary commands on the host and fully compromise the system.
Affected Systems
The affected product is OpenEQUELLA from openequella. Versions before 2026.1.0 contain the flaw; no specific patch version list is provided beyond the release that fixes the issue.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is high severity. The EPSS score is not available and the CVE is not listed in CISA KEV. Attackers need authentication to inject into permissible templates, but once authenticated they can achieve complete remote code execution. The risk is significant for installations that expose template editing capabilities to users with sufficient privileges.
OpenCVE Enrichment