CVE-2026-11815

An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Un atacante que intercepta y manipula el tráfico entre la aplicación cliente y el servidor API Gateway podría potencialmente deserializar objetos arbitrarios. Esta vulnerabilidad podría conducir a expectativas de seguridad rotas o a ejecución remota de código.

10 Jun 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 07:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-11815

Mitre link : CVE-2026-11815

CVE.ORG link : CVE-2026-11815


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data