CVE-2026-94109: openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Injection
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runtime.exec for arbitrary command execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
openEQUELLAto a version that resolves this vulnerability.Fixed in 2026.1.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated openEQUELLA user can exploit it. The attack vector is network-accessible and requires no user interaction, but it does require low-level privileges.
Which application features can carry the malicious input?
Malicious FreeMarker expressions can be injected through collection summaries, dashboard portlets, or MIME templates.
What level of access can successful exploitation provide?
Successful exploitation allows arbitrary command execution through dangerous FreeMarker classes and Runtime.exec. The listed impact includes high confidentiality, integrity, and availability impact.
What version resolves the vulnerability?
The issue affects openEQUELLA versions before 2026.1.0. Upgrade to version 2026.1.0 or later.