๐Ÿ” CVE Alert

CVE-2026-94109

HIGH 8.8

openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Injection

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runtime.exec for arbitrary command execution.

CWE CWE-1336
Vendor openequella
Product openequella
Published Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for openequella openequella

Be the first to know when new high vulnerabilities affecting openequella openequella are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

openequella / openEQUELLA
0 < 2026.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openequella/openEQUELLA/commit/d6e165afc986f8a3ed912cdb367d5ad8c1eeab5c github.com: https://github.com/openequella/openEQUELLA/releases/tag/2026.1.0 github.com: https://github.com/openequella/openEQUELLA/blob/8bd24b1dcf26cc3d74757e6b982fc1971a7d6767/Source/Plugins/Core/com.equella.core/src/com/tle/web/freemarker/BasicConfiguration.java github.com: https://github.com/openequella/openEQUELLA/blob/8bd24b1dcf26cc3d74757e6b982fc1971a7d6767/Source/Plugins/Core/com.equella.core/src/com/tle/web/portal/standard/renderer/FreemarkerPortletRenderer.java#L141-L170 github.com: https://github.com/openequella/openEQUELLA/blob/8bd24b1dcf26cc3d74757e6b982fc1971a7d6767/Source/Plugins/Core/com.equella.core/src/com/tle/core/entity/service/impl/AbstractEntityServiceImpl.java#L230-L250 github.com: https://github.com/openequella/openEQUELLA vulncheck.com: https://www.vulncheck.com/advisories/openequella-before-2026.1.0-remote-code-execution-via-freemarker-template-injection

Credits

๐Ÿ” evan