CVE-2026-15538

MEDIUM

primefaces primereact API ObjectUtils.mutateFieldData prototype pollution

Title source: cna
STIX 2.1

Description

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-377888 | primefaces primereact API ObjectUtils.mutateFieldData prototype pollution
https://vuldb.com/vuln/377888
Signature, Permissions Required signature permissions-required
VDB-377888 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377888/cti
Third Party Advisory third-party-advisory
CVE-2026-15538 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15538
Third Party Advisory third-party-advisory
Submit #855024 | Node.js primereact 10.9.8 Prototype Pollution
https://vuldb.com/submit/855024
Issue Tracking issue-tracking
https://github.com/Mantle-UI/mantle-ui/issues/50

Scores

CVSS v3 6.3
EPSS 0.0026
EPSS Percentile 17.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1321 CWE-94
Status published
Products (9)
primefaces/primereact 10.9.0
primefaces/primereact 10.9.1
primefaces/primereact 10.9.2
primefaces/primereact 10.9.3
primefaces/primereact 10.9.4
primefaces/primereact 10.9.5
primefaces/primereact 10.9.6
primefaces/primereact 10.9.7
primefaces/primereact 10.9.8
Published Jul 13, 2026
Tracked Since Jul 13, 2026