Vulnerability record · CVE-2020-26217 · published 16 November 2020
CVE-2020-26217: XStream blocklist bypass allows remote code execution
Xstream · Xstream
XStream before 1.4.14 can be tricked into deserializing attacker-controlled input that leads to OS command execution. Only deployments relying on XStream blocklists are affected; those using the Security Framework allowlist are not. The flaw is fixed in 1.4.14.
Description
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high EPSS and public exploit material, though it requires low privileges and only affects blocklist-based deployments.
What it is
XStream before 1.4.14 can be tricked into deserializing attacker-controlled input that leads to OS command execution. Only deployments relying on XStream blocklists are affected; those using the Security Framework allowlist are not. The flaw is fixed in 1.4.14.
Impact
A remote attacker who can supply the processed input stream can run arbitrary shell commands in the context of the application, giving full compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network by submitting a crafted serialized stream to an application that uses XStream with blocklist-based protection. The CVSS vector indicates low privileges are required and no user interaction, so any authenticated or otherwise low-privileged input path is sufficient.
Exploitation
Not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high (0.85, 99.7th percentile) and the vendor advisory is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade XStream to 1.4.14 or later.
- Replace blocklist-based protection with XStream's Security Framework allowlist.
- Apply the code workarounds in the vendor advisory where upgrading is not immediately possible.
- Update dependent products (Debian, NetApp, Apache ActiveMQ/Camel, Oracle) to versions carrying the fix.
- Restrict network and input paths that feed untrusted data into XStream deserialization.
Detection
- Search application and server logs for XStream deserialization errors or unexpected class-loading exceptions.
- Monitor for child processes spawned by Java application servers (e.g. shell, curl, wget) that are not part of normal operation.
- Inventory code and dependencies for XStream versions below 1.4.14 and for blocklist-based configurations.
- Alert on outbound network connections from application hosts following deserialization activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-26217 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-26217), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.