CVE-2026-1691

MEDIUM

bolo-solo < 2.6.4 - Remote Code Execution via SnakeYAML Deserialization

Title source: llm
STIX 2.1

Description

A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component SnakeYAML. Such manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.343485
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.343485
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.741899

Scores

CVSS v3 6.3
EPSS 0.0050
EPSS Percentile 38.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-502
Status published
Products (1)
adlered/bolo-solo < 2.6.4
Published Jan 30, 2026
Tracked Since Feb 18, 2026