CVE-2024-5986: 
Java vulnerability analysis and mitigation

Overview

CVE-2024-5986 is an arbitrary file write vulnerability in h2oai/h2o-3 version 3.46.0.1 that allows unauthenticated remote attackers to write arbitrary data to any file on the server. The vulnerability was published on February 2, 2026, and was reported via the Huntr bug bounty platform. It carries a CVSS v3.0 base score of 9.1 (Critical), reflecting its network-accessible, no-authentication-required attack vector with high integrity and availability impact (Feedly, Huntr).

Technical details

The root cause is classified as CWE-73 (External Control of File Name or Path), where the application fails to properly restrict attacker-controlled input from influencing file system operations. Exploitation involves a two-step process: first, an attacker sends a crafted request to the /3/Parse endpoint to inject attacker-controlled data as the header of an empty file; second, the /3/Frames/framename/export endpoint is used to export that frame, writing the malicious header content to an arbitrary location on the server's file system. No authentication is required, and the attack can be performed entirely over the network with low complexity (Feedly, Huntr).

Impact

Successful exploitation allows an attacker to overwrite any file accessible to the h2o-3 service account, including sensitive files such as private SSH keys, cron scripts, or authorized_keys files. This can lead to remote code execution and complete unauthorized access to the underlying system. The vulnerability has no confidentiality impact per the CVSS scoring, but the integrity and availability impacts are rated High, and the practical consequence of overwriting critical system files can result in full system compromise (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00124 (0.124%), indicating a currently low probability of exploitation in the near term. The vulnerability was detected by Qualys scanners (detection IDs 5007322 and 5007345), suggesting it is being tracked by vulnerability management platforms (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible h2o-3 instances running version 3.46.0.1 using network scanning tools or Shodan, targeting the default h2o-3 REST API port (typically 54321).
  2. Craft malicious parse request: Send a crafted HTTP POST request to the /3/Parse endpoint, injecting attacker-controlled content as the header field of an empty or minimal data frame. The header value contains the payload to be written to the target file.
  3. Trigger file export: Send a request to the /3/Frames/framename/export endpoint, specifying the target file path on the server (e.g., /root/.ssh/authorized_keys or a cron script path) as the export destination.
  4. Achieve persistence or RCE: The exported frame writes the attacker-controlled header data to the specified file path. If an SSH public key is written to authorized_keys, the attacker can authenticate via SSH; if a script file is overwritten, code execution can be triggered on the next scheduled run (Feedly, Huntr).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /3/Parse with unusual or encoded header values from external or untrusted IP addresses; HTTP requests to /3/Frames/*/export specifying file paths outside normal data directories.
  • Logs: h2o-3 access logs showing requests to /3/Parse and /3/Frames/framename/export endpoints in rapid succession from the same source IP; export paths referencing system directories (e.g., /root/, /home/, /etc/, /var/spool/cron/).
  • File System: Unexpected modifications to ~/.ssh/authorized_keys or other SSH configuration files; newly created or modified cron job files; changes to script files owned by the h2o-3 service account with recent timestamps.
  • Process: Unexpected SSH logins from unknown keys or IP addresses following h2o-3 API activity; new processes spawned from cron or init that were not previously present.

Mitigation and workarounds

Patch information for a fixed version of h2o-3 is not confirmed as available at the time of reporting (Feedly). Organizations should immediately implement network-level access controls to restrict access to the h2o-3 REST API (default port 54321), limiting it to trusted internal IP ranges only. Apply the principle of least privilege to the service account running h2o-3 to minimize the impact of potential file overwrites. Monitor for suspicious file write activity in sensitive directories and consider disabling or rate-limiting the /3/Parse and /3/Frames/framename/export endpoints if not required for operations. Check the Huntr bounty page and the h2oai/h2o-3 GitHub repository for patch releases.

Community reactions

A technical write-up on the vulnerability was published at infinitsec.net, providing details on the remote arbitrary file write mechanism in h2o-3 (infinitsec). The vulnerability was also noted in a CISA weekly vulnerability summary for the week of February 2, 2026, indicating it received attention from the broader security community (RedPacket Security). No significant vendor statements or major researcher commentary beyond the Huntr disclosure have been identified.

Additional resources


Source: This report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103922CRITICAL9.3
  • JavaScript logoJavaScript
  • com.capacitorjs:core
NoYesOct 01, 2026
CVE-2026-61741CRITICAL9.3
  • Java logoJava
  • org.http4s:http4s-scala-xml_2.12
NoYesSep 24, 2026
CVE-2026-54049HIGH8.7
  • Java logoJava
  • org.sakaiproject.rubrics:rubrics-impl
NoNoOct 01, 2026
CVE-2026-100660HIGH8.7
  • Java logoJava
  • io.netty:netty-codec-http3
NoNoSep 26, 2026
CVE-2026-61586HIGH8.2
  • Java logoJava
  • eu.copernik:copernik-xml-factory
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management