CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)
UNSUPPORTED WHEN ASSIGNED Deserialization of Untrusted Data vulnerability in Apache Shindig.
This issue affects Apache Shindig: all versions.
Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Apache Shindig instance (including the Shindig OpenSocial REST API) so only trusted users can reach it, since users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66256?
CVE-2026-66256 is rated with a risk score of 82, indicating a high severity vulnerability.
How do I fix CVE-2026-66256?
There is no available fix for CVE-2026-66256 as Apache Shindig is unsupported when assigned this vulnerability.
What type of vulnerability is CVE-2026-66256?
CVE-2026-66256 is a Remote Code Execution vulnerability caused by deserialization of untrusted data.
Which versions of Apache Shindig are affected by CVE-2026-66256?
CVE-2026-66256 affects all versions of Apache Shindig.
What can an attacker do with CVE-2026-66256?
An attacker can exploit CVE-2026-66256 to execute arbitrary code on the server by sending specially-crafted requests to the Shindig REST API.