CVE-2026-27727 is a critical vulnerability in mchange-commons-java, a library used by applications like c3p0, that allows for remote code execution. It stems from an independent JNDI implementation that can download and execute malicious code if an attacker provides a specially crafted JAXAX.naming.Reference or serialized object. This bypasses JDK hardening measures, enabling high-impact attacks. The vulnerability carries a high CVSS score of 8.9, indicating a severe risk. An attacker can exploit this remotely with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. No known workarounds exist, making patching to version 0.4.0 or later essential. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation. It is not currently listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.0CPE matchmatch criteria | cpe:2.3:a:mchange:mchange_commons_java:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.