


Perceptive Security
SOC/SIEM Consultancy

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component
in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache …
Published:
27 July 2026 at 22:00:00
Alert date:
28 July 2026 at 17:04:58
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A critical deserialization vulnerability (CWE-502) exists in the Tribes-based clustering component of Apache Axis2/Java through version 2.0.0 when deployed on Apache Tomcat. The flaw allows an unauthenticated remote attacker with network access to the clustering port to execute arbitrary code by delivering a crafted serialized Java object to the cluster channel. The vulnerable code path is in org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. The vulnerability is only exploitable when Tribes clustering is explicitly enabled, which is off by default. Apache has addressed the issue in version 2.0.1 by completely removing the clustering feature. Users are strongly advised to upgrade to version 2.0.1 immediately. The fix is confirmed via a commit to the official Apache Axis2 Java core GitHub repository.
Technical details
Mitigation steps:
Affected products:
Apache Axis2/Java 2.0.0 and earlier
Apache Tomcat
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-66713
https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15
https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728
http://www.openwall.com/lists/oss-security/2026/07/28/2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
