https://seclists.org/oss-sec/2026/q3/290: CVE-2026-66713: Apache Axis2/Java: deserialization of untrusted Data
Published Jul 27, 2026
·Updated
Affected Software
1 affected component
Apache Software Foundation Apache Axis2/Java<=2.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-66713?
The severity of CVE-2026-66713 is rated as low.
2
Which versions of Apache Axis2/Java are affected by CVE-2026-66713?
Apache Axis2/Java through version 2.0.0 is affected by CVE-2026-66713.
3
What vulnerability type is described in CVE-2026-66713?
CVE-2026-66713 describes a deserialization of untrusted data vulnerability (CWE-502).
4
In which component of Apache Axis2/Java does CVE-2026-66713 occur?
CVE-2026-66713 occurs in the Tribes-based clustering component of Apache Axis2/Java.
5
Is Tribes clustering enabled by default in Apache Axis2/Java, affecting CVE-2026-66713?
No, Tribes clustering is not enabled by default in Apache Axis2/Java.