CVE-2026-15538

medium Red Hat
CVSS v3 Base Score
6.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.3%
Exploitation probability in 30 days
Top 83% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
Low
Integrity
Low
Availability
Low
Published: July 13, 2026 (55 days ago)
Last Modified: July 13, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in PrimeFaces PrimeReact. A remote attacker can exploit a weakness in the ObjectUtils.mutateFieldData function within the component API. This allows for the improper modification of object prototype attributes, potentially leading to unexpected behavior or further attacks. This vulnerability affects products that are no longer supported by the maintainer.

CWE

CWE-915

Affected Products

Red Hat Enterprise Linux AI (RHEL AI) 3

References