CVE-2026-15563 - Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos
CVE ID :CVE-2026-15563
Published : Aug. 11, 2026, 8:49 a.m. | 38 minutes ago
Description :A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 11, 2026, 8:49 a.m. | 38 minutes ago
Description :A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...