CVE-2026-46495Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-25)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-23: 1Mentions · 2026-06-25: 2PoC Mentioned / Linked · 2026-06-25: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-25: 2Technical Details · 2026-06-23: 1Technical Details · 2026-06-25: 206-2306-25
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-231
Disclosure1
2026-06-252
Disclosure1Patch1
Full discourse3 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A critical CVSS 9.2 Java deserialization vulnerability allows an OpenDJ unauthenticated RCE. Patch CVE-2026-46495 immediately to protect your servers. #OpenDJ #RCE #CVE202646495 #Vulnerability #Cybersecurity https://securityonline.info/opendj-unauthenticated-rce https://t.co/iBFooTFAoM

    Post summary

    The tweet announces CVE-2026-46495, a critical Java deserialization flaw in OpenDJ enabling unauthenticated RCE with a CVSS score of 9.2, and urges users to apply the patch immediately.

    00091616
    12.8K followersView on X
  • yousukezan@yousukezan
    Disclosure

    OpenDJのLDAPディレクトリサービスで、認証なしで遠隔から任意コードを実行できる重大な脆弱性が見つかった。影響を受ける環境ではネットワーク経由でサーバーが乗っ取られる可能性があり、CVE-2026-46495として公開された。CVSSスコアは9.2である。 この脆弱性はJavaのデシリアライゼーション処理に起因するもので、CWE-502(信頼できないデータのデシリアライゼーション)に分類される。OpenDJは認証を行う前にJMX RMIコネクタへ送られたデータを処理するため、攻撃者は細工したデータを送信することで任意のコマンドを実行できる。攻撃にはJMX Connection Handlerが待ち受けるTCPポートへネットワーク経由で接続できるだけで十分で、クライアント証明書や認証情報は不要とされる。 OpenDJはLDAPv3準拠のディレクトリサービスで、Java上で動作し、組織のID情報を管理する用途で利用される。SQLやNoSQLクラスタをバックエンドとして利用できるほか、システム監視のためJMX Connection Handlerを有効にして運用している環境もあり、その場合は攻撃対象が広がるとしている。 この問題はOpenDJ Community Edition 5.1.0以前に影響し、研究者はバージョン4.4.15で攻撃を実証した。公開済みの概念実証(PoC)コードも存在する一方、現時点で実際の悪用は確認されていないという。修正版はOpenDJ Community Edition 5.1.1で提供されており、利用者には速やかな更新が推奨されている。CVE-2026-46495。 https://securityonline.info/opendj-unauthenticated-rce/

    Post summary

    CV‑E-2026-46495, a severe unauthenticated RCE in OpenDJ due to Java deserialization, has been publicly disclosed with a PoC available but no confirmed active exploitation; the 5.1.1 patch is urged to remediate.

    000111.2K
    14.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI (CVE-2026-46495) OpenDJ's JMX RMI connector deserializes untrusted data before authentication. The JMX Connection Handler reads and processes attacker-controlled bytes prior to any auth check, letting an unauthenticated remote attacker deserialize arbitrary Java objects on the directory server and achieve remote code execution. The handler is disabled by default but is commonly enabled for monitoring integrations. Exploitation needs only TCP reachability to the JMX listener - no credentials, prior privileges, or client certificates - with impact depending on the runtime classpath and Java version. Unauthenticated RCE was demonstrated on OpenDJ 4.4.15 (JDK 11 + Jackson 2.12.6.1). 👉Upgrade to OpenDJ 5.1.1.

    Post summary

    OpenDJ suffers an unauthenticated RCE through JMX RMI Java deserialization; the post detailed the vulnerability and recommends upgrading to OpenDJ 5.1.1, with no PoC or evidence of active exploitation presented.

    0000086
    226 followersView on X

Explore more