CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core.
Older unsupported versions may also be affected.
Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache MyFaces (MyFaces Core)to a version that resolves this vulnerability.Fixed in 2.3.12 - Upgrade
Upgrade
Apache MyFaces (MyFaces Core)to a version that resolves this vulnerability.Fixed in 2.3-next-M9 - Upgrade
Upgrade
Apache MyFaces (MyFaces Core)to a version that resolves this vulnerability.Fixed in 3.0.4 - Upgrade
Upgrade
Apache MyFaces (MyFaces Core)to a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
Apache MyFaces (MyFaces Core)to a version that resolves this vulnerability.Fixed in 4.1.4