CVE-2026-41586

CRITICAL

Hyperledger Fabric 1.0.0-2.2.26 fabric-sdk-java - Java Deserialization Remote Code Execution

Title source: manual
STIX 2.1

Description

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://hyperledger.github.io/fabric-gateway

Scores

CVSS v4 9.3
EPSS 0.0041
EPSS Percentile 32.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
hyperledger/fabric >= 1.0.0, <= 2.2.26
org.hyperledger.fabric-sdk-java/fabric-sdk-java 1.0.0 - 2.2.26Maven
Published May 07, 2026
Tracked Since May 07, 2026