CVE-2019-10086
Executive Summary
CVE-2019-10086 exposes a flaw in Apache Commons Beanutils 1.9.2 where a custom BeanIntrospector can enable attackers to access the Java classloader through the ubiquitous 'class' property on any object. This bypasses the default protection in PropertyUtilsBean, potentially allowing remote code execution or sensitive data disclosure. The vulnerability is not listed in CISA KEV and requires patching or configuration changes to mitigate.
Authoritative CVE Metadata - CVSS Base Score: 7.3 (HIGH) - Published: 2019-08-20T21:15:12.057 - Last Modified: 2026-08-25T16:28:27.310
Original Description: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
"Slow down and everything you are chasing will come around and catch you."
— John De Paola