Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-68536: Apache MyFaces may load internal resources without permission
CVE-2026-68536 · published 9 days ago
Summary
Certain versions of Apache MyFaces can be told to access internal network locations or read files on the server, which could expose sensitive information. This affects the core component of the MyFaces library, especially older unsupported releases. Updating to version 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4 resolves the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache myfaces | <= 2.2.15 |
Original advisory text
Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core.
Older unsupported versions may also be affected.
Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Older unsupported versions may also be affected.
Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-918Server-Side Request Forgery (SSRF)
Timeline
Published16 Sep 2026
Updated25 Sep 2026
First seen16 Sep 2026
Track software like this
Free during beta