CVE-2026-11796: Medium severity Asset Suite vulnerability
Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet and ResourceBundleReloadServlet, which could result in denial-of-service conditions affecting application availability. These servlets are designed to perform specific functions within production environment depending on how the Asset Suite application is configured.
Affected Software
Event History
Frequently Asked Questions
Who can trigger the denial-of-service condition?
Unauthenticated users can access the affected servlets. No authenticated account is required based on the available information.
Which application functions are exposed?
The affected endpoints are PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet, and ResourceBundleReloadServlet. Their operational effect depends on how the Asset Suite application is configured in the production environment.
What is the practical impact of exploitation?
Access to these servlets could result in denial-of-service conditions that affect application availability.