{"id":"CVE-2026-46581","published":"2026-08-05T12:18:57.190","lastModified":"2026-08-10T17:26:01.393","description":"In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the privileges of the target server. This could allow access to restricted files such as `WEB-INF/web.xml` or `/etc/passwd`.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-22","CWE-94","CWE-641"],"vendors":["eclipse"],"products":["mojarra"],"references":[{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/160","tags":["Vendor Advisory"]},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544","tags":["Exploit","Vendor Advisory"]}],"exploitRefs":[{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544","tags":["Exploit","Vendor Advisory"]},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/544","tags":["Exploit","Vendor Advisory"]}],"hasPoc":true,"ai":{"summary":"The flaw allows remote URLs to be included in Facelet processing, potentially exposing sensitive files. This matters because it can lead to unauthorized access to critical server files.","exploitability":"Exploitation requires control over a URL parameter and access to the affected Eclipse Mojarra version; moderate effort needed.","blast_radius":"If exploited, could grant access to restricted files like `WEB-INF/web.xml` or `/etc/passwd`, impacting server security significantly.","remediation":"Update to the latest Eclipse Mojarra version to mitigate this vulnerability.","tags":["web","rce","facelet","url-inclusion"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:59:21.147Z"}}