{"id":"CVE-2020-26217","title":"XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream","summary":"XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are aff…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"xstream","product":"xstream","affected":["xstream < 1.4.14","debian_linux = 9.0","debian_linux = 10.0","snapmanager","activemq < 5.15.14","activemq = 5.16.0","banking_cash_management = 14.2","banking_cash_management = 14.3","banking_cash_management = 14.5","banking_corporate_lending_process_management = 14.2","banking_corporate_lending_process_management = 14.3","banking_corporate_lending_process_management = 14.5","banking_credit_facilities_process_management = 14.2","banking_credit_facilities_process_management = 14.3","banking_credit_facilities_process_management = 14.5","banking_platform = 2.4.0","banking_platform = 2.7.1","banking_platform = 2.9.0","banking_supply_chain_finance = 14.2","banking_supply_chain_finance = 14.3","banking_supply_chain_finance = 14.5","banking_trade_finance_process_management = 14.2","banking_trade_finance_process_management = 14.3","banking_trade_finance_process_management = 14.5","banking_virtual_account_management = 14.2.0","banking_virtual_account_management = 14.3.0","banking_virtual_account_management = 14.5.0","business_activity_monitoring = 11.1.1.9.0","business_activity_monitoring = 12.2.1.3.0","business_activity_monitoring = 12.2.1.4.0","communications_policy_management = 12.5.0","endeca_information_discovery_studio = 3.2.0.0","retail_xstore_point_of_service = 16.0.6","retail_xstore_point_of_service = 17.0.4","retail_xstore_point_of_service = 18.0.3","retail_xstore_point_of_service = 19.0.2"],"patched":["xstream 1.4.14","activemq 5.15.14"],"published":"2020-11-16","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:17.070","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-26217","references":[{"url":"https://github.com/x-stream/xstream/commit/0fec095d534126931c99fd38e9c6d41f5c685c1a","label":"security-advisories@github.com"},{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2","label":"security-advisories@github.com"},{"url":"https://lists.apache.org/thread.html/r2de526726e7f4db4a7cb91b7355070779f51a84fd985c6529c2f4e9e%40%3Cissues.activemq.apache.org%3E","label":"security-advisories@github.com"},{"url":"https://lists.apache.org/thread.html/r7c9fc255edc0b9cd9567093d131f6d33fde4c662aaf912460ef630e9%40%3Ccommits.camel.apache.org%3E","label":"security-advisories@github.com"},{"url":"https://lists.apache.org/thread.html/r826a006fda71cc96fc87b6eca4b5d195f19a292ad36cea501682c38c%40%3Cissues.activemq.apache.org%3E","label":"security-advisories@github.com"},{"url":"https://lists.apache.org/thread.html/redde3609b89b2a4ff18b536a06ef9a77deb93d47fda8ed28086fa8c3%40%3Cissues.activemq.apache.org%3E","label":"security-advisories@github.com"},{"url":"https://lists.debian.org/debian-lts-announce/2020/12/msg00001.html","label":"security-advisories@github.com"},{"url":"https://security.netapp.com/advisory/ntap-20210409-0004/","label":"security-advisories@github.com"},{"url":"https://www.debian.org/security/2020/dsa-4811","label":"security-advisories@github.com"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security-advisories@github.com"},{"url":"https://x-stream.github.io/CVE-2020-26217.html","label":"security-advisories@github.com"},{"url":"https://github.com/x-stream/xstream/commit/0fec095d534126931c99fd38e9c6d41f5c685c1a","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r2de526726e7f4db4a7cb91b7355070779f51a84fd985c6529c2f4e9e%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r7c9fc255edc0b9cd9567093d131f6d33fde4c662aaf912460ef630e9%40%3Ccommits.camel.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r826a006fda71cc96fc87b6eca4b5d195f19a292ad36cea501682c38c%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/redde3609b89b2a4ff18b536a06ef9a77deb93d47fda8ed28086fa8c3%40%3Cissues.activemq.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/12/msg00001.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210409-0004/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4811","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://x-stream.github.io/CVE-2020-26217.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","exploit-available"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T18:50:40.221561Z"},"epss":0.85001,"epssPercentile":0.9971,"exploits":{"github":6,"githubRepos":["https://github.com/novysodope/CVE-2020-26217-XStream-RCE-POC","https://github.com/Al1ex/CVE-2020-26217","https://github.com/epicosy/XStream-1"],"nuclei":["CVE-2020-26217"],"checkedAt":"2026-10-08T08:12:25.896Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T19:44:15.638Z","slug":"CVE-2020-26217","body":"## Overview\n\nXStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.\n\n## Affected\n\n- `xstream < 1.4.14`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `snapmanager`\n- `activemq < 5.15.14`\n- `activemq = 5.16.0`\n- `banking_cash_management = 14.2`\n- `banking_cash_management = 14.3`\n- `banking_cash_management = 14.5`\n- `banking_corporate_lending_process_management = 14.2`\n- `banking_corporate_lending_process_management = 14.3`\n- `banking_corporate_lending_process_management = 14.5`\n- `banking_credit_facilities_process_management = 14.2`\n- `banking_credit_facilities_process_management = 14.3`\n- `banking_credit_facilities_process_management = 14.5`\n- `banking_platform = 2.4.0`\n- `banking_platform = 2.7.1`\n- `banking_platform = 2.9.0`\n- `banking_supply_chain_finance = 14.2`\n- `banking_supply_chain_finance = 14.3`\n- `banking_supply_chain_finance = 14.5`\n- `banking_trade_finance_process_management = 14.2`\n- `banking_trade_finance_process_management = 14.3`\n- `banking_trade_finance_process_management = 14.5`\n- `banking_virtual_account_management = 14.2.0`\n- `banking_virtual_account_management = 14.3.0`\n- `banking_virtual_account_management = 14.5.0`\n- `business_activity_monitoring = 11.1.1.9.0`\n- `business_activity_monitoring = 12.2.1.3.0`\n- `business_activity_monitoring = 12.2.1.4.0`\n- `communications_policy_management = 12.5.0`\n- `endeca_information_discovery_studio = 3.2.0.0`\n- `retail_xstore_point_of_service = 16.0.6`\n- `retail_xstore_point_of_service = 17.0.4`\n- `retail_xstore_point_of_service = 18.0.3`\n- `retail_xstore_point_of_service = 19.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `xstream 1.4.14`\n- `activemq 5.15.14`","depth":"midnight","depthScore":73,"depthScoreParts":{"impact":44,"likelihood":17,"exploitation":12,"ransomware":0},"changes":[]}