Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)
Full Disclosuremailing list archivesFrom: disclosure via Fulldisclosure <fulldis 2026-8-18 06:17:38 Author: seclists.org(查看原文) 阅读量:3 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:04:05 +0000

0day Rubbish Research Team is publicly disclosing a vulnerability in ObjectDB 2.9.5 server mode (ObjectDB Software). 
The research is published and a proof-of-concept is available.

Pre-authentication RCE (default credentials) (CVSS 9.8, pre-authentication)

ObjectDB 2.9.5 server mode (port 6136, proprietary binary protocol) has a critical remote code execution vulnerability: 
JDOQL query filter evaluation allows arbitrary static-method reflective invocation. Factory default credentials 
admin/admin grant full privileges with no forced change; the IP check accepts any source IP when the user has no ip 
attribute. A malicious JDOQL filter such as java.lang.Runtime.getRuntime().exec(cmd) != null is evaluated server-side: 
QNF.q() loads any class (no class-name allowlist), MCN.l() calls Method.invoke with setAccessible(true), reaching 
Runtime.exec - the server-side Java process runs as root, yielding uid=0(root) RCE. Dynamically verified.

Impact: Full read of the host filesystem and JVM environment as root, arbitrary OS command execution, and full control 
of the ObjectDB host and database.

Advisory: https://0day-rubbish.com/blog/objectdb-jdoql-injection-root-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software) disclosure via Fulldisclosure (Aug 17)

文章来源: https://seclists.org/fulldisclosure/2026/Aug/58
如有侵权请联系:admin#unsafe.sh