External risk intelligence

OpenDJ JMX RMI Connector Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-46495

The vulnerability affects the JMX RMI connector in OpenDJ, which is disabled by default. Directory service management interfaces like JMX are typically restricted to internal administrative networks and are not intended to be exposed to the public internet in standard deployment patterns.

Deserialization

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in OpenDJ, a directory service technology, which could allow unauthenticated remote attackers to execute arbitrary code. While exploitation requires specific conditions, including the JMX connector being enabled and reachable, the potential for severe impact necessitates awareness. The main concern is confirming if this specific component is active and exposed within our environment.

  • Unauthenticated code execution in OpenDJ.
  • Critical vulnerability impacting directory services.
  • Confirm exposure of JMX RMI connector.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted serialized Java object to a running OpenDJ server that has its JMX Connection Handler enabled and its TCP listener accessible. This could lead to the attacker executing arbitrary code on the server.

  • Unauthenticated remote access required.
  • Crafted serialized Java object sent.
  • Arbitrary code execution on server.

Live Threat

Current exploitation, exposure, and threat context

When the JMX Connection Handler is enabled and its TCP listener is reachable, an unauthenticated remote attacker could achieve code execution within the OpenDJ server process by submitting a crafted serialized Java object. This exploitation is dependent on the runtime classpath and Java version, and was demonstrated against OpenDJ 4.4.15 on JDK 11 with Jackson 2.12.6.1.

  • Server process code execution.
  • Remote code execution via JMX RMI.
  • Compromise of directory service.

Operational Fix

Recommended remediation, mitigation, and detection steps

The OpenDJ server's JMX RMI connector is the likely area of concern for this vulnerability. Teams responsible for directory services, identity management, or core infrastructure platforms should investigate. The first practical step is to determine if the JMX Connection Handler is enabled and if its TCP listener is accessible externally, as exploitation requires this specific configuration. If so, confirm the accountable owner for the OpenDJ instance and assess its criticality before planning remediation.

  • Identify OpenDJ JMX RMI connector usage.
  • Verify JMX listener accessibility and criticality.
  • Plan remediation or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is OpenDJ?

OpenDJ is a directory service built to manage identity information, such as user accounts and credentials, using the LDAPv3 standard. It provides centralized storage for authentication and authorization data within an enterprise infrastructure. This vulnerability specifically concerns the JMX RMI connector, a management interface used for monitoring and controlling the server's operations.

What does CWE-502 mean for CVE-2026-46495?

CWE-502 refers to 'Deserialization of Untrusted Data.' In this case, the OpenDJ server fails to properly validate incoming Java objects sent to the JMX connector before processing them. Because the system trusts these objects implicitly, an attacker can supply a specially crafted object that forces the server to execute malicious code instead of performing standard management tasks.

Does this vulnerability trigger if JMX is disabled?

No. The JMX Connection Handler is disabled by default in OpenDJ. This flaw only exists when the handler is manually enabled and its associated TCP listener is reachable on the network. If the service is not listening for JMX traffic, the specific path required to send the malicious serialized object is not available to an attacker.

Is my environment at risk from this CVE?

According to Halo Surface Signal, risk is unlikely for most because JMX interfaces are typically restricted to internal administrative networks and are not intended for public access. You should be concerned if your OpenDJ instance has the JMX Connection Handler active and is reachable from outside your secure management perimeter.

How do I start addressing this issue?

Your first step is to check your OpenDJ configuration to determine if the JMX Connection Handler is enabled. If it is active, verify whether the TCP listener is accessible from unauthorized segments of your network. Once you have identified the status of this component, coordinate with your infrastructure team to update OpenDJ to version 5.1.1 or later to apply the necessary security fixes.

References