CVE-2026-94109
openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Injection
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runtime.exec for arbitrary command execution.
| CWE | CWE-1336 |
| Vendor | openequella |
| Product | openequella |
| Published | Sep 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for openequella openequella
Be the first to know when new high vulnerabilities affecting openequella openequella are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
openequella / openEQUELLA
0 < 2026.1.0
References
github.com: https://github.com/openequella/openEQUELLA/commit/d6e165afc986f8a3ed912cdb367d5ad8c1eeab5c github.com: https://github.com/openequella/openEQUELLA/releases/tag/2026.1.0 github.com: https://github.com/openequella/openEQUELLA/blob/8bd24b1dcf26cc3d74757e6b982fc1971a7d6767/Source/Plugins/Core/com.equella.core/src/com/tle/web/freemarker/BasicConfiguration.java github.com: https://github.com/openequella/openEQUELLA/blob/8bd24b1dcf26cc3d74757e6b982fc1971a7d6767/Source/Plugins/Core/com.equella.core/src/com/tle/web/portal/standard/renderer/FreemarkerPortletRenderer.java#L141-L170 github.com: https://github.com/openequella/openEQUELLA/blob/8bd24b1dcf26cc3d74757e6b982fc1971a7d6767/Source/Plugins/Core/com.equella.core/src/com/tle/core/entity/service/impl/AbstractEntityServiceImpl.java#L230-L250 github.com: https://github.com/openequella/openEQUELLA vulncheck.com: https://www.vulncheck.com/advisories/openequella-before-2026.1.0-remote-code-execution-via-freemarker-template-injection
Credits
๐ evan