{"id":"CVE-2019-13116","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-13116","summary":"The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections","details":"The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections","published":"2019-10-16T20:15:11.103","modified":"2026-06-17T02:16:05.717","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://docs.mulesoft.com/release-notes/mule-runtime/mule-3.8.0-release-notes"},{"type":"EXPLOIT","url":"https://threat.tevora.com/mulesoft-3-8-unauthenticated-rce/"},{"type":"WEB","url":"https://docs.mulesoft.com/release-notes/mule-runtime/mule-3.8.0-release-notes"},{"type":"EXPLOIT","url":"https://threat.tevora.com/mulesoft-3-8-unauthenticated-rce/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T02:16:05.717"}}