---
id: CVE-2026-15538
title: A weakness has been identified in primefaces primereact up to 10.9.8
summary: >-
  A weakness has been identified in primefaces primereact up to 10.9.8. This
  issue affects the function ObjectUtils.mutateFieldData of the component API.
  This manipulation of the argument Field causes improperly controlled
  modification of …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-94
  - CWE-1321
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15538'
references:
  - url: 'https://github.com/Mantle-UI/mantle-ui/issues/50'
    label: cna@vuldb.com
  - url: 'https://github.com/primefaces/primereact/'
    label: cna@vuldb.com
  - url: 'https://github.com/primefaces/primereact/issues/8553'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-15538'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/855024'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377888'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377888/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-13T07:25:22.919Z'
epss: 0.00536
epssPercentile: 0.42779
---

## Overview

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
