JBoss EAP IIOP NS Auth Bypass: Unauthenticated Bind Hijacks JNDI
CVE-2026-15563 Published on August 11, 2026
Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
Vulnerability Analysis
CVE-2026-15563 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 74 days later.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-15563
stack.watch emails you whenever new vulnerabilities are published in Red Hat Jboss Enterprise Application Platform or Red Hat Jbosseapxp. Just hit a watch button to start following.