CVE-2026-68536 PUBLISHED

Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

Assigner: apache
Reserved: 30.07.2026 Published: 16.09.2026 Updated: 16.09.2026

Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core.

Older unsupported versions may also be affected. 

Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

Product Status

Vendor Apache Software Foundation
Product Apache MyFaces
Versions Default: unaffected
  • affected from 2.2.0-beta to 2.2.15 (incl.)
  • Version 2.3.0 is affected
  • affected from 2.3-next-M1 to 2.3-next-M9 (excl.)
  • affected from 2.3.1 to 2.3.12 (excl.)
  • affected from 3.0.0 to 3.0.4 (excl.)
  • affected from 4.0.0 to 4.0.4 (excl.)
  • affected from 4.1.0 to 4.1.4 (excl.)

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE