CVE-2026-46495: Jmx Authenticator Object Array Cast
JMXAuthenticator implementation inappropriately casts credentials to generic `Object[]`. When paired with missing JEP 290 deserialization filters (`jmx.remote.rmi.server.credentials.filter.pattern`), this permits unauthenticated attackers to supply a malicious gadget chain array, leading to Remote Code Execution. Explicitly enforce strong types (e.g., `insta
greprules fetch cve-2026-46495-jmx-authenticator-object-array-cast --engine opengrepDescription
JMXAuthenticator implementation inappropriately casts credentials to generic `Object[]`. When paired with missing JEP 290 deserialization filters (`jmx.remote.rmi.server.credentials.filter.pattern`), this permits unauthenticated attackers to supply a malicious gadget chain array, leading to Remote Code Execution. Explicitly enforce strong types (e.g., `insta
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.