Posted by evan via Fulldisclosure on Sep 26 SUMMARY: an authenticated deserialization vuln in openEQUELLA allows an attacker to inject a SignedObject payload, unwrap the SignedObject, create an LDAP callback and serve a JNR response to get the server to execute arbitrary code. alongside this sink is a SSTI vuln as well. https://blog.evan.lat/posts/openeq/ openequella is an "open source digital repository" for educational material. it is widely used in australian…
openEQUELLA authenticated RCE chain(s)
About this summary. This is a short, independently written summary of an article first published by Full Disclosure. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/fulldisclosure/2026/Sep/80
Source attribution: headline and facts are from Full Disclosure (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.



