CVE-2026-52751: Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection

Published Jun 10, 2026
·
Updated

Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code that allows unauthenticated remote code execution. Attackers can craft a malicious project file with a ghidra:// URL that, when opened via File → Open Project, deserializes untrusted objects using a Jython 2.7.4 gadget chain to execute arbitrary commands.

Affected Software

2 affected components
National Security Agency Ghidra<12.1
NSA Ghidra<12.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Ghidra to a version that resolves this vulnerability.

    Fixed in 12.1
  2. Configuration

    Disable or avoid using the client-side Shared-Project RMI connection feature (Shared Project) until Ghidra is upgraded to 12.1.

    Ghidra (client Shared-Project RMI) shared_project_rmi_connection = disabled
  3. Configuration

    Do not open project files via ghidra:// URLs; unregister the ghidra:// protocol handler or otherwise block opening ghidra:// links until the product is patched.

    Ghidra (URL handling) ghidra:// protocol handling = do not open/unregister
  4. Configuration

    Disable Jython scripting support or remove the bundled Jython runtime to prevent exploitation via the Jython 2.7.4 gadget chain until Ghidra is patched.

    Ghidra (Jython scripting) jython_enabled = false
  5. Compensating control

    Restrict or block access to Shared-Project RMI endpoints from untrusted networks using firewall rules, ACLs, or network segmentation to prevent unauthenticated RMI connections.

  6. Operational

    If untrusted ghidra project files were opened, assume potential compromise: investigate affected hosts, perform forensics, rotate any potentially exposed credentials, and restore systems from known-good backups as appropriate.

Event History

Jun 10, 2026
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-52751?

CVE-2026-52751 has a high severity rating of 8.6.

2

How do I fix CVE-2026-52751?

To fix CVE-2026-52751, upgrade to Ghidra version 12.1 or later where the vulnerability has been patched.

3

What type of attack does CVE-2026-52751 enable?

CVE-2026-52751 enables unauthenticated remote code execution due to unsafe deserialization.

4

Is there a patch available for CVE-2026-52751?

Yes, a patch is available in Ghidra version 12.1 to mitigate CVE-2026-52751.

5

What software does CVE-2026-52751 affect?

CVE-2026-52751 affects the National Security Agency's Ghidra software before version 12.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203