Impact
The vulnerability originates from the FreemarkerPortletRenderer’s renderHtml method, which processes a stored markup field without sandboxing or restricting the FreeMarker TemplateClassResolver. An authenticated non‑guest user can store a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. When any user renders a dashboard containing the affected portlet, the untrusted markup is passed directly to custFactory.createResult, allowing the use of built‑in directives such as ?new and freemarker.template.utility.Execute. This capability is sufficient to invoke Runtime.exec and execute arbitrary commands within the application‑server process, resulting in remote code execution.
Affected Systems
OpenEQUELLA versions prior to 2026.1.0 are affected; the issue is addressed in the 2026.1.0 release. No finer version granularity is provided.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of < 1% reflects a low probability of exploitation at present. The CVE is not listed in CISA’s KEV catalog. Attackers must be authenticated, but once authenticated they can inject into persistent templates and cause remote code execution when the content is displayed. The risk is therefore significant for installations that expose the rendering endpoint to users with the required privileges.
OpenCVE Enrichment