← Vulnerability feed

Vulnerability record · CVE-2020-7961 · published 20 March 2020

CVE-2020-7961: Liferay Portal JSONWS deserialization allows remote code execution

Liferay · Liferay Portal

Liferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not safely handled, a remote attacker can supply crafted serialized content that leads to arbitrary code execution on the server. This is a critical, network-reachable flaw in a widely deployed enterprise portal platform.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing and near-maximum EPSS score make this an urgent patching priority.

What it is

Liferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not safely handled, a remote attacker can supply crafted serialized content that leads to arbitrary code execution on the server. This is a critical, network-reachable flaw in a widely deployed enterprise portal platform.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the Liferay Portal process, giving full control over the application server and any data or credentials it can reach.

Attack surface

Reached over the network through Liferay Portal's JSONWS interface; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

The vulnerability is listed in CISA KEV (added 2021-11-03) and has an EPSS 30-day probability of 0.99905, and references include an exploit-tagged Check Point research writeup, indicating active exploitation in the wild.

What to do

  • Upgrade Liferay Portal to 7.2.1 CE GA2 or later, or apply the vendor's patch for this issue.
  • If immediate upgrade is not possible, restrict network access to JSONWS endpoints to trusted sources only.
  • Disable or block unused JSONWS services and review exposed web service endpoints.
  • Monitor vendor advisories and CISA KEV guidance for updated remediation instructions.

Detection

  • Inspect web server and application logs for unusual POST requests to JSONWS endpoints, especially with serialized Java payload patterns.
  • Alert on outbound network connections or process spawning from the Liferay Portal server that are not part of normal operations.
  • Use the Check Point and Packet Storm proof-of-concept details to build signatures for known exploitation attempts.
  • Monitor for unexpected file writes or new processes on hosts running Liferay Portal.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-7961 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Liferay Portal Deserialization of Untrusted Data Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7961 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-33990Liferay portal os command injection vulnerabilityLiferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…EPSS 12%9.8CVE-2022-42120Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up…EPSS 0.78%9.8CVE-2022-42122Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…EPSS 0.77%9.8CVE-2019-16891Liferay Portal CE JSON deserialization remote command executionLiferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 …EPSS 45%analysed8.8CVE-2024-38002Liferay digital experience platform missing authorization vulnerabilityThe workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…EPSS 0.61%8.8CVE-2024-26271Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…EPSS 0.36%8.8CVE-2024-26272Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%8.8CVE-2024-26273Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2020-7961), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.