CVE-2026-71374
Received Received - Intake

Deserialization of Untrusted Data in Cosminexus Component Container

Vulnerability report for CVE-2026-71374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Hitachi, Ltd.

Description

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
hitachi cosminexus_component_container From 09-00 (inc) to 11-70 (inc)
hitachi ucosminexus_developer From 09-00 (inc) to 11-70 (inc)
hitachi application_server From 09-00 (inc) to 11-70 (inc)
hitachi service_platform From 09-00 (inc) to 11-70 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71374 is a critical deserialization vulnerability in Hitachi Cosminexus Component Container. It allows remote attackers to execute arbitrary code by processing untrusted serialized data, potentially leading to full system compromise. The vulnerability affects multiple versions of Cosminexus products across different platforms.

Impact Analysis

This vulnerability can allow attackers to take control of affected systems, steal data, install malware, or disrupt services. Since it has a CVSS score of 9.8, it is highly severe and can impact confidentiality, integrity, and availability of systems running vulnerable versions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR and HIPAA. Organizations using affected versions may face legal penalties, data breach notifications, and reputational damage due to non-compliance with data protection regulations.

Mitigation Strategies

Immediately upgrade Cosminexus Component Container to the latest patched versions (e.g., 09-70-28, 09-87-10, 11-20-10, 11-60-03, 11-70-03) based on your current version. Verify the update through Hitachi's official support channels.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71374. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart