« Volver al listado

CVE-2026-12894

Estado: Pendiente de análisisAlta (8.8)—

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N con PR:L indica servicio remoto con privilegios; Qute engine falla en bloquear acceso a funciones Java internas, permitiendo ejecución de comandos en el servidor. La escalada de privilegios es implícita en 'take control of the server'.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-12894",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-12894",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-31T14:32:37.234748Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "Quarkus",
          "product": "quarkus-qute",
          "versions": [
            {
              "status": "affected",
              "version": "3.27.0",
              "lessThan": "3.27.5.SP1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.33.0",
              "lessThan": "3.33.3.SP1",
              "versionType": "semver"
            }
          ],
          "packageName": "io.quarkus:quarkus-qute",
          "collectionURL": "https://repo1.maven.org/maven2",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:camel_quarkus:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
          "packageName": "camel-quarkus-qute",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:camel_quarkus:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
          "packageName": "camel-quarkus-qute-component",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:camel_quarkus:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Apache Camel 4 for Quarkus 3",
          "packageName": "quarkus-qute",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jbosseapxp"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "packageName": "camel-quarkus-qute",
          "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jbosseapxp"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "packageName": "camel-quarkus-qute-component",
          "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:jbosseapxp"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat JBoss Enterprise Application Platform Expansion Pack",
          "packageName": "quarkus-qute",
          "collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-31T13:17:20.753",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:62515",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:62555",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:63302",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-12894",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2491319",
      "source": "secalert@redhat.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1336"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue exists in the component responsible for looking up data values (ReflectionValueResolver), which fails to properly block access to sensitive Java internal functions when processing certain data types like Enums. An attacker who can provide or influence the template text can exploit this bypass to take control of the server by executing unauthorized commands."
    }
  ],
  "lastModified": "2026-09-11T18:16:56.137",
  "sourceIdentifier": "secalert@redhat.com"
}