CVEFinder.io

CVE-2026-94301

ā›” critical
šŸ” Scan for this CVE
Summary

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the Ā 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14

Description

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the
Ā 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

CVSS Score
9.8
Critical
EPSS Score
0.4
Exploit Probability
Published Date
2026-09-21
First Seen: 2026-09-24
šŸ“Š Relative Risk Intelligence

This CVE is Very High Risk - more severe than 90.5% of all 361,609 vulnerabilities in our database.

#34,236
Top 10% most severe
Severity Percentile
šŸŽÆ CISA SSVC Assessment Updated: Sep 21, 2026
šŸ” Exploitation Status
None
No known exploits
āš™ļø Automatable
YES
Can be exploited automatically
šŸ’„ Technical Impact
Total
Complete system compromise possible
šŸ† Discovered By
tonghuaroot
SSVC data provided by CISA
Last Modified 2026-09-22
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

šŸ“¦ Affected Products 0

No affected products information available

šŸ”— References 2