CRITICAL
CVE-2026-68536
CVSS
9.8
Description
Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core.
Older unsupported versions may also be affected.
Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.
Weakness (CWE)
CWE-918
Server-Side Request Forgery (SSRF)
EPSS Score
0.47%
Probability of exploitation in next 30 days
40.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.