CVE-2026-15554: Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery
in depth analysis: https://docs.google.com/document/d/1XdX8AJzGjBgCLE0UZ5NRGGrzQ14HSVS8HcDgH0X70w/edit?tab=t.d440c4doqxdr#bookmark=kix.axzzwc7bbq6o
An external security assessment of Red Hat JBoss EAP 7 identified that the Undertow AJP listener on default port 8009 honours forged sslcert and isssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
Other sources
the Undertow AJP listener honours forged sslcert and isssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
Deployments with an Undertow AJP listener reachable directly over TCP on port 8009 are exposed. The assessment identified this condition in Red Hat JBoss EAP 7.
Does an attacker need credentials or user interaction?
No. Exploitation is described as unauthenticated and requires no user interaction, but the attacker must have direct TCP access to the AJP listener.
What type of authentication can be bypassed?
CLIENT-CERT authentication can be bypassed by injecting forged ssl_cert and is_ssl attributes through the AJP protocol. The issue relies on the listener accepting those attributes without shared-secret authentication.