Description
In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse eclipse Mojarra
Vendors & Products Eclipse
Eclipse eclipse Mojarra

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Facelet Inclusion Allowing Unauthorized File Disclosure in Eclipse Mojarra wildfly-clustering-faces-mojarra: com.sun.faces:jsf-impl: org.glassfish:jakarta.faces: mojarra: Unauthenticated RCE in EAP JSF applications via EL injection in ui:include
References
Metrics threat_severity

None

threat_severity

Important


Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Facelet Inclusion Allowing Unauthorized File Disclosure in Eclipse Mojarra

Wed, 05 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.
Weaknesses CWE-22
CWE-641
CWE-94
References

Subscriptions

Eclipse Eclipse Mojarra
cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-08-05T14:38:08.035Z

Reserved: 2026-07-08T14:11:22.752Z

Link: CVE-2026-46581

cve-icon Vulnrichment

Updated: 2026-08-05T14:34:59.921Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-06T12:01:27Z

Links: CVE-2026-46581 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T10:07:06Z

Weaknesses