← All Advisories

CVE-2026-6857

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-6857

Key Details

CVECVE-2026-6857
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-23
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Red Hat build of Apache Camel 4 for Quarkus 3 and Red Hat Red Hat Fuse 7
Classified asCWE-502 (Deserialization of Untrusted Data)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat build of Apache Camel 4 for Quarkus 3
Red HatRed Hat Fuse 7
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6857
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-6857