cbcvebase.
CVE-2025-26866
published 2025-12-12

CVE-2025-26866: A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces…

PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.80%
53.0th percentile
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachehugegraph>= 1.0.0 < 1.7.01.7.0
apache_software_foundationapache_hugegraph-server>= 1.0.0 < 1.7.01.7.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts targeting insecure Hessian deserialization in the PD store (org.apache.hugegraph:hg-pd-core); monitor for unexpected Raft node join requests from unauthorized IPs attempting to exploit object injection via Hessian serialization.
  • Alert on Raft cluster membership changes originating from IPs not explicitly whitelisted in the cluster configuration, as the fix enforces IP-based authentication to restrict cluster membership.
  • Flag any Java deserialization activity in hg-pd-core involving classes outside a strict whitelist; the vulnerability allows arbitrary object injection via Hessian deserialization.
  • ·Affected component is org.apache.hugegraph:hg-pd-core; only versions prior to 1.7.0 are vulnerable. Upgrade to 1.7.0 to receive the IP-based authentication enforcement and Hessian class whitelist fix.
  • ·Despite a high EPSS exploitation probability percentile (82.1), no public exploit or CISA KEV entry exists as of the publication date (December 12, 2025).

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.