CVE-2021-36981

HIGH

verinice < 1.22.2 - Authenticated Remote Code Execution via Unsafe Java Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-36981. PoCs published by 0xBrAinsTorM.

AI-analyzed exploit summary This repository contains a functional Python script that exploits CVE-2021-36981, an unsafe Java deserialization vulnerability in Verinice.Pro 1.22.1. The script uses ysoserial to generate gadgets and sends them to a target endpoint, supporting both brute-force and targeted exploitation.

Description

In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

Exploits (1)

nomisec WORKING POC
by 0xBrAinsTorM · poc
https://github.com/0xBrAinsTorM/CVE-2021-36981

This repository contains a functional Python script that exploits CVE-2021-36981, an unsafe Java deserialization vulnerability in Verinice.Pro 1.22.1. The script uses ysoserial to generate gadgets and sends them to a target endpoint, supporting both brute-force and targeted exploitation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Verinice.Pro 1.22.1
Auth required
Prerequisites: Authenticated session (JSESSIONID cookie) · ysoserial JAR file · Target endpoint URL
mistral-large-3 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0605
EPSS Percentile 92.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
sernet/verinice < 1.22.2
Published Aug 31, 2021
Tracked Since Feb 18, 2026