{"id":"CVE-2026-94301","published":"2026-09-21T15:17:38.903","lastModified":"2026-09-22T04:18:02.810","description":"The fix for CVE-2026-47065/ZDRES-232 (\"resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy\"), released on 2026-06-02 and announced as \"Fully addressed\" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the\n 2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-502"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/rzos6zds5x7obl8trkvznt1djw4f996p","tags":[]},{"url":"https://lists.apache.org/thread/x4667tn5ozbvkc3wz87lhzogbfl0dczj","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows for an allow-list bypass via java.lang.reflect.Proxy due to missing resolveProxyClass() override in MINA 2.0.X and 2.1.X branches, enabling potential remote code execution.","exploitability":"Exploitation requires access to the affected software version and specific conditions; however, once met, it can lead to severe consequences.","blast_radius":"If exploited, this vulnerability could result in unauthorized access and control over systems using these MINA versions, leading to significant data breaches or system compromise.","remediation":"Upgrade all affected MINA versions (2.0.X and 2.1.X) to the latest available releases that include the resolveProxyClass() override fix.","tags":["rce","proxy","mina","java","security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:02:15.309Z"}}