CVE-2026-15554: Red Hat JBoss Enterprise Application Platform 7

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate via the AJP protocol.

Affected products

  • Red Hat Red Hat JBoss Enterprise Application Platform 7
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4.25: before 2.2.40.SP3-redhat-00001 (fixed in 2.2.40.SP3-redhat-00001)
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 7: before 0:2.16.0-22.redhat_00057.1.el7eap (fixed in 0:2.16.0-22.redhat_00057.1.el7eap); before 0:2.3.14-11.SP11_redhat_00001.1.el7eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el7eap); before 0:1.5.26-2.Final_redhat_00001.1.el7eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el7eap); before 0:2.18.8-1.redhat_00003.1.el7eap (fixed in 0:2.18.8-1.redhat_00003.1.el7eap); before 0:5.0.31-3.SP2_redhat_00001.1.el7eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el7eap); before 0:1.10.0-46.Final_redhat_00044.1.el7eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el7eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 8: before 0:2.16.0-22.redhat_00057.1.el8eap (fixed in 0:2.16.0-22.redhat_00057.1.el8eap); before 0:2.3.14-11.SP11_redhat_00001.1.el8eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el8eap); before 0:1.5.26-2.Final_redhat_00001.1.el8eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el8eap); before 0:2.18.8-1.redhat_00003.1.el8eap (fixed in 0:2.18.8-1.redhat_00003.1.el8eap); before 0:5.0.31-3.SP2_redhat_00001.1.el8eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el8eap); before 0:1.10.0-46.Final_redhat_00044.1.el8eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el8eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 7.4 Els On Rhel 9: before 0:2.16.0-22.redhat_00057.1.el9eap (fixed in 0:2.16.0-22.redhat_00057.1.el9eap); before 0:2.3.14-11.SP11_redhat_00001.1.el9eap (fixed in 0:2.3.14-11.SP11_redhat_00001.1.el9eap); before 0:1.5.26-2.Final_redhat_00001.1.el9eap (fixed in 0:1.5.26-2.Final_redhat_00001.1.el9eap); before 0:2.18.8-1.redhat_00003.1.el9eap (fixed in 0:2.18.8-1.redhat_00003.1.el9eap); before 0:5.0.31-3.SP2_redhat_00001.1.el9eap (fixed in 0:5.0.31-3.SP2_redhat_00001.1.el9eap); before 0:1.10.0-46.Final_redhat_00044.1.el9eap (fixed in 0:1.10.0-46.Final_redhat_00044.1.el9eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 10: before 0:2.40.0-8.redhat_00024.1.el10eap (fixed in 0:2.40.0-8.redhat_00024.1.el10eap); before 0:4.1.7-1.SP1_redhat_00001.1.el10eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el10eap); before 0:2.0.5-1.Final_redhat_00001.1.el10eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el10eap); before 0:1.85.0-1.redhat_00001.1.el10eap (fixed in 0:1.85.0-1.redhat_00001.1.el10eap); before 0:1.2.7-1.redhat_00002.1.el10eap (fixed in 0:1.2.7-1.redhat_00002.1.el10eap); before 0:801.8.0-1.GA_redhat_00001.1.el10eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el10eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 8: before 0:2.40.0-8.redhat_00024.1.el8eap (fixed in 0:2.40.0-8.redhat_00024.1.el8eap); before 0:4.1.7-1.SP1_redhat_00001.1.el8eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el8eap); before 0:2.0.5-1.Final_redhat_00001.1.el8eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el8eap); before 0:1.85.0-1.redhat_00001.1.el8eap (fixed in 0:1.85.0-1.redhat_00001.1.el8eap); before 0:1.2.7-1.redhat_00002.1.el8eap (fixed in 0:1.2.7-1.redhat_00002.1.el8eap); before 0:801.8.0-1.GA_redhat_00001.1.el8eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el8eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform 8.1 For Rhel 9: before 0:2.40.0-8.redhat_00024.1.el9eap (fixed in 0:2.40.0-8.redhat_00024.1.el9eap); before 0:4.1.7-1.SP1_redhat_00001.1.el9eap (fixed in 0:4.1.7-1.SP1_redhat_00001.1.el9eap); before 0:2.0.5-1.Final_redhat_00001.1.el9eap (fixed in 0:2.0.5-1.Final_redhat_00001.1.el9eap); before 0:1.85.0-1.redhat_00001.1.el9eap (fixed in 0:1.85.0-1.redhat_00001.1.el9eap); before 0:1.2.7-1.redhat_00002.1.el9eap (fixed in 0:1.2.7-1.redhat_00002.1.el9eap); before 0:801.8.0-1.GA_redhat_00001.1.el9eap (fixed in 0:801.8.0-1.GA_redhat_00001.1.el9eap); …
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

Published 2026-08-11. Last modified 2026-09-25.