CVE-2026-46495: OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
Description
A Deserialization of Untrusted Data (CWE-502) issue in OpenDJ’s JMX RMI connector allows an unauthenticated remote attacker to deserialize arbitrary Java objects on the server. The vulnerability exists because the platform reads and processes attacker-controlled bytes prior to authentication. This affects OpenDJ Community Edition through 5.1.0. This has been patched in version 5.1.1.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-46495 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →