---
id: CVE-2020-26217
title: >-
  XStream before version 1.4.14 is vulnerable to Remote Code Execution.The
  vulnerability may allow a remote attacker to run arbitrary shell commands only
  by manipulating the processed input stream
summary: >-
  XStream before version 1.4.14 is vulnerable to Remote Code Execution.The
  vulnerability may allow a remote attacker to run arbitrary shell commands only
  by manipulating the processed input stream. Only users who rely on blocklists
  are aff…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: xstream
product: xstream
affected:
  - xstream < 1.4.14
  - debian_linux = 9.0
  - debian_linux = 10.0
  - snapmanager
  - activemq < 5.15.14
  - activemq = 5.16.0
  - banking_cash_management = 14.2
  - banking_cash_management = 14.3
  - banking_cash_management = 14.5
  - banking_corporate_lending_process_management = 14.2
  - banking_corporate_lending_process_management = 14.3
  - banking_corporate_lending_process_management = 14.5
  - banking_credit_facilities_process_management = 14.2
  - banking_credit_facilities_process_management = 14.3
  - banking_credit_facilities_process_management = 14.5
  - banking_platform = 2.4.0
  - banking_platform = 2.7.1
  - banking_platform = 2.9.0
  - banking_supply_chain_finance = 14.2
  - banking_supply_chain_finance = 14.3
  - banking_supply_chain_finance = 14.5
  - banking_trade_finance_process_management = 14.2
  - banking_trade_finance_process_management = 14.3
  - banking_trade_finance_process_management = 14.5
  - banking_virtual_account_management = 14.2.0
  - banking_virtual_account_management = 14.3.0
  - banking_virtual_account_management = 14.5.0
  - business_activity_monitoring = 11.1.1.9.0
  - business_activity_monitoring = 12.2.1.3.0
  - business_activity_monitoring = 12.2.1.4.0
  - communications_policy_management = 12.5.0
  - endeca_information_discovery_studio = 3.2.0.0
  - retail_xstore_point_of_service = 16.0.6
  - retail_xstore_point_of_service = 17.0.4
  - retail_xstore_point_of_service = 18.0.3
  - retail_xstore_point_of_service = 19.0.2
patched:
  - xstream 1.4.14
  - activemq 5.15.14
published: '2020-11-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:17.070'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-26217'
references:
  - url: >-
      https://github.com/x-stream/xstream/commit/0fec095d534126931c99fd38e9c6d41f5c685c1a
    label: security-advisories@github.com
  - url: >-
      https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r2de526726e7f4db4a7cb91b7355070779f51a84fd985c6529c2f4e9e%40%3Cissues.activemq.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r7c9fc255edc0b9cd9567093d131f6d33fde4c662aaf912460ef630e9%40%3Ccommits.camel.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/r826a006fda71cc96fc87b6eca4b5d195f19a292ad36cea501682c38c%40%3Cissues.activemq.apache.org%3E
    label: security-advisories@github.com
  - url: >-
      https://lists.apache.org/thread.html/redde3609b89b2a4ff18b536a06ef9a77deb93d47fda8ed28086fa8c3%40%3Cissues.activemq.apache.org%3E
    label: security-advisories@github.com
  - url: 'https://lists.debian.org/debian-lts-announce/2020/12/msg00001.html'
    label: security-advisories@github.com
  - url: 'https://security.netapp.com/advisory/ntap-20210409-0004/'
    label: security-advisories@github.com
  - url: 'https://www.debian.org/security/2020/dsa-4811'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security-advisories@github.com
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security-advisories@github.com
  - url: 'https://x-stream.github.io/CVE-2020-26217.html'
    label: security-advisories@github.com
  - url: >-
      https://github.com/x-stream/xstream/commit/0fec095d534126931c99fd38e9c6d41f5c685c1a
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r2de526726e7f4db4a7cb91b7355070779f51a84fd985c6529c2f4e9e%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r7c9fc255edc0b9cd9567093d131f6d33fde4c662aaf912460ef630e9%40%3Ccommits.camel.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r826a006fda71cc96fc87b6eca4b5d195f19a292ad36cea501682c38c%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/redde3609b89b2a4ff18b536a06ef9a77deb93d47fda8ed28086fa8c3%40%3Cissues.activemq.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/12/msg00001.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210409-0004/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2020/dsa-4811'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://x-stream.github.io/CVE-2020-26217.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-07T18:50:40.221561Z'
epss: 0.85001
epssPercentile: 0.99709
exploits:
  github: 6
  githubRepos:
    - 'https://github.com/novysodope/CVE-2020-26217-XStream-RCE-POC'
    - 'https://github.com/Al1ex/CVE-2020-26217'
    - 'https://github.com/epicosy/XStream-1'
  nuclei:
    - CVE-2020-26217
  checkedAt: '2026-10-07T19:44:51.103Z'
exploitAvailable: true
ingestedAt: '2026-10-07T19:44:15.638Z'
---

## Overview

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

## Affected

- `xstream < 1.4.14`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `snapmanager`
- `activemq < 5.15.14`
- `activemq = 5.16.0`
- `banking_cash_management = 14.2`
- `banking_cash_management = 14.3`
- `banking_cash_management = 14.5`
- `banking_corporate_lending_process_management = 14.2`
- `banking_corporate_lending_process_management = 14.3`
- `banking_corporate_lending_process_management = 14.5`
- `banking_credit_facilities_process_management = 14.2`
- `banking_credit_facilities_process_management = 14.3`
- `banking_credit_facilities_process_management = 14.5`
- `banking_platform = 2.4.0`
- `banking_platform = 2.7.1`
- `banking_platform = 2.9.0`
- `banking_supply_chain_finance = 14.2`
- `banking_supply_chain_finance = 14.3`
- `banking_supply_chain_finance = 14.5`
- `banking_trade_finance_process_management = 14.2`
- `banking_trade_finance_process_management = 14.3`
- `banking_trade_finance_process_management = 14.5`
- `banking_virtual_account_management = 14.2.0`
- `banking_virtual_account_management = 14.3.0`
- `banking_virtual_account_management = 14.5.0`
- `business_activity_monitoring = 11.1.1.9.0`
- `business_activity_monitoring = 12.2.1.3.0`
- `business_activity_monitoring = 12.2.1.4.0`
- `communications_policy_management = 12.5.0`
- `endeca_information_discovery_studio = 3.2.0.0`
- `retail_xstore_point_of_service = 16.0.6`
- `retail_xstore_point_of_service = 17.0.4`
- `retail_xstore_point_of_service = 18.0.3`
- `retail_xstore_point_of_service = 19.0.2`

## Remediation

Upgrade past the affected range:

- `xstream 1.4.14`
- `activemq 5.15.14`
