CVE-2026-3967 | Alfresco Activiti up to 7.19/8.8.0 Process Variable Serialization System SerializableType.java deserialize/createObjectInputStream deserialization (EUVD-2026-11492)
A vulnerability has been found in Alfresco Activiti up to 7.19/8.8.0 and classified as critical. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. This manipulation causes deserialization.
This vulnerability is registered as CVE-2026-3967. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.