← Back to search

CVE-2026-94301

9.8 CRITICAL

Published 2026-09-21 · Updated 2026-09-22

AI risk analysis

Summary
The flaw allows for an allow-list bypass via java.lang.reflect.Proxy due to missing resolveProxyClass() override in MINA 2.0.X and 2.1.X branches, enabling potential remote code execution.
Exploitability
Exploitation requires access to the affected software version and specific conditions; however, once met, it can lead to severe consequences.
Blast radius
If exploited, this vulnerability could result in unauthorized access and control over systems using these MINA versions, leading to significant data breaches or system compromise.
Prioritized remediation
Upgrade all affected MINA versions (2.0.X and 2.1.X) to the latest available releases that include the resolveProxyClass() override fix.
rceproxyminajavasecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed to the  2.2.X branch only. The 2.0.X and 2.1.X maintenance branches never received the resolveProxyClass() override, so the 2.0.29 and 2.1.13 artifacts listed as fixed -- and every later release on those lines, up to and including the current 2.0.30 and 2.1.14 -- remain vulnerable to the exact allow-list bypass that CVE-2026-47065 was meant to close.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.