CVE-2026-51368

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint

Published 2026-08-25. Last modified 2026-08-31.