CVE-2026-42779 is an incomplete-fix vulnerability in Apache MINA's object deserialization handling. In affected releases, AbstractIoBuffer.resolveClass() contains a branch for static classes or primitive types that resolves a class without first enforcing the configured classname allowlist (acceptMatchers). This permits an attacker to bypass the intended class filter during deserialization performed through IoBuffer.getObject(). The issue resulted because the prior fix for CVE-2026-41635 was not applied to the Apache MINA 2.1.x and 2.2.x branches. Apache MINA 2.1.0 through 2.1.11 and 2.2.0 through 2.2.6 are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a self-contained Java PoC suite for CVE-2026-42779, a deserialization filter bypass in Apache MINA's AbstractIoBuffer.resolveClass() affecting MINA 2.1.0-2.1.11 and 2.2.0-2.2.6. The exploit is not tied to a public exploit framework; it consists of three standalone Java programs, a Dockerfile, a Makefile, and a Bash entrypoint wrapper. Structure and purpose: - FilterBypassPoC.java: demonstrates the core logic flaw by showing that MINA acceptMatchers can be bypassed for type-0 descriptors such as primitives, non-Serializable classes, and arrays. It uses IoBuffer.putObject()/getObject() locally to prove that disallowed classes still deserialize. - CraftedBypassPoC.java: shows the more realistic attacker technique. It manually crafts a MINA-compatible serialized stream by overriding ObjectOutputStream.writeClassDescriptor() to emit type-0 descriptors for all classes, then wraps the stream in MINA's 4-byte length-prefixed format. This bypasses the allowlist for arbitrary Serializable classes and nested object graphs. - RcePoC.java: escalates the bypass to code execution using a Commons Collections 3.2.2 gadget chain (ConstantTransformer -> InvokerTransformer -> Runtime.getRuntime().exec()). It crafts the same type-0 MINA payload and proves execution by creating /tmp/CVE-2026-42779-RCE-PROOF. - Dockerfile, Makefile, and entrypoint.sh: provide reproducible build/run paths for all three PoCs. - README.md: documents affected versions, root cause, exploitation flow, prerequisites, and remediation. Main exploit capability: remote exploitation of vulnerable MINA services that deserialize attacker-controlled objects over the network using ObjectSerializationCodecFactory or IoBuffer.getObject(). The exploit bypasses the intended class allowlist and can load arbitrary gadget-chain classes if present on the target classpath. In the included RCE demonstration, this results in arbitrary OS command execution. Network/targeting details: the code does not hardcode a remote IP, hostname, or HTTP endpoint. Instead, it targets any network-reachable Apache MINA endpoint using the vulnerable object deserialization path. The crafted payload format is MINA-specific: a 4-byte length prefix followed by a Java serialized object stream with attacker-forced type-0 class descriptors. Overall assessment: this is a real exploit repository, not just a detector. It contains working local PoCs for filter bypass and a practical RCE demonstration, but the payload is basic and hardcoded rather than operator-customizable, so maturity is best classified as OPERATIONAL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A class-name allowlist bypass in Apache MINA's AbstractIoBuffer.resolveClass() permits arbitrary code execution in applications calling IoBuffer.getObject(). CVE-2026-42779 covers the omission of an earlier fix from the 2.1.x and 2.2.x branches, affecting versions 2.1.0–2.1.11 and 2.2.0–2.2.6. The advisory assigns a critical CVSS v3 score of 9.8. Upgrade to 2.1.12 or 2.2.7, respectively.
A vulnerability in Oracle Enterprise Manager Cloud Control addressed by the September 15, 2026 patch release; no further technical details are provided.
A named vulnerability additionally addressed by an Oracle Enterprise Manager patch; no technical details are provided.
A severe remote code execution vulnerability in Apache MINA caused by a logic flaw in AbstractIoBuffer.resolveClass() that bypasses the acceptMatchers filter and enables full object deserialization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.