← Vulnerability feed

Vulnerability record · CVE-2019-16891 · published 4 October 2019

CVE-2019-16891: Liferay Portal CE JSON deserialization remote command execution

Liferay · Liferay Portal

Liferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 deserialization issue rated 9.8 critical, and public exploit write-ups and a video exist, making it a practical target for internet-facing portals.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit references, and a very high EPSS score make this an urgent patch.

What it is

Liferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 deserialization issue rated 9.8 critical, and public exploit write-ups and a video exist, making it a practical target for internet-facing portals.

Impact

An attacker can run arbitrary commands on the portal host, leading to full compromise of confidentiality, integrity and availability of the application and its data.

Attack surface

Reachable over the network via a crafted JSON request to the portal; the CVSS vector shows no authentication and no user interaction required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.447 (98.7th percentile) and multiple references are tagged Exploit, indicating public exploit material is available.

What to do

  • Upgrade Liferay Portal CE to a fixed release from the official downloads page; 6.2.5 is the only version named in the record.
  • If upgrade is not immediately possible, restrict network access to the portal and place it behind authentication or a WAF.
  • Disable or block untrusted JSON deserialization endpoints where feasible.
  • Monitor vendor advisories for the specific patched version, since the record does not list one.

Detection

  • Inspect HTTP requests for JSON bodies containing serialization gadget markers or unexpected class names.
  • Alert on outbound connections or process creation from the portal server that are not part of normal operation.
  • Review portal logs for deserialization errors or unusual JSON payloads preceding command execution.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-16891 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7961Liferay Portal JSONWS deserialization allows remote code executionLiferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not sa…KEVEPSS 100%analysed9.8CVE-2021-33990Liferay portal os command injection vulnerabilityLiferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…EPSS 12%9.8CVE-2022-42120Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up…EPSS 0.78%9.8CVE-2022-42122Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…EPSS 0.77%8.8CVE-2024-38002Liferay digital experience platform missing authorization vulnerabilityThe workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…EPSS 0.61%8.8CVE-2024-26271Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…EPSS 0.36%8.8CVE-2024-26272Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%8.8CVE-2024-26273Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2019-16891), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.