CVE-2025-43797
Java vulnerability analysis and mitigation

Overview

CVE-2025-43797 is an insecure default initialization vulnerability in Liferay Portal and Liferay DXP that allows any registered user to automatically join newly created sites due to an "Open" default membership type. It affects Liferay Portal versions 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions. The vulnerability was published on September 15, 2025, with the GitHub Advisory following on September 16, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Liferay Advisory).

Technical details

The root cause is classified as CWE-1188 (Insecure Default Initialization of Resource): when a new site is created in Liferay Portal or DXP, the default membership type is set to "Open," meaning any registered user can join without administrator approval. An attacker with a valid low-privilege account can exploit this by simply joining any newly created site and then leveraging site membership permissions to view, add, or edit site content. The affected Maven package is com.liferay:com.liferay.site.admin.web, with versions below 5.0.111 being vulnerable. No complex attack prerequisites or special conditions are required beyond having a registered account on the platform (GitHub Advisory, Liferay Advisory).

Impact

A remote attacker with a low-privilege registered account can exploit this vulnerability to gain unauthorized site membership, potentially viewing restricted site content (confidentiality impact), and adding or editing content within the site (integrity impact). Availability is not impacted. The scope is limited to the vulnerable system, with no evidence of lateral movement to subsequent systems; however, unauthorized content manipulation could affect the integrity of business-critical information hosted on affected Liferay sites (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.164% (0.00164), indicating a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability has been detected by Qualys scanners (detection IDs 520075 and 733443).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Liferay Portal or DXP instances running affected versions (Portal 7.1.0–7.4.3.111, DXP 7.3 GA–update 35, 7.4 GA–update 92, 2023.Q3.1–2023.Q3.4, or 2023.Q4.0) using tools like Shodan or Censys.
  2. Account Registration: Register a low-privilege user account on the target Liferay instance, or use an existing registered account.
  3. Identify Open Sites: Browse the site directory or use Liferay's site listing features to identify newly created sites with the default "Open" membership type.
  4. Join the Site: Use the self-service site membership feature to join the target site without requiring administrator approval, exploiting the insecure default membership setting.
  5. Access and Manipulate Content: Once a site member, leverage the membership permissions to view restricted site content, add new content, or edit existing content within the site (GitHub Advisory, Liferay Advisory).

Indicators of compromise

  • Logs: Unexpected site membership join events in Liferay audit logs for newly created sites, particularly from accounts with no prior association to those sites; multiple membership requests from the same user account across different sites in a short timeframe.
  • Application Behavior: Newly created sites showing a high number of members shortly after creation; content additions or edits by users who are not expected site contributors.
  • Administrative Alerts: Liferay admin panel showing site membership type as "Open" for sites that should be restricted; unexpected content changes logged in site activity feeds.

Mitigation and workarounds

Liferay has released a patch in the Maven package com.liferay:com.liferay.site.admin.web version 5.0.111 and later. For Liferay Portal, upgrade to version 7.4.3.112 or later; for DXP, upgrade beyond the affected versions (7.3 update 35, 7.4 update 92, 2023.Q3.4, or 2023.Q4.0). As an immediate workaround, administrators should review all existing sites and manually change the membership type from "Open" to "Restricted" or "Private" to prevent unauthorized self-enrollment. Additionally, implement stricter access controls for site creation and regularly audit site membership policies (GitHub Advisory, Liferay Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10050HIGH8.7
  • Java logoJava
  • apache-activemq-artemis
NoYesAug 04, 2026
CVE-2026-59920MEDIUM6.5
  • Java logoJava
  • management-api-5.0
NoYesJul 29, 2026
CVE-2026-59898MEDIUM6.3
  • Java logoJava
  • kayenta-2026.1
NoYesJul 29, 2026
CVE-2026-53573MEDIUM4.8
  • Java logoJava
  • org.geonetwork-opensource:geonetwork
NoYesJul 31, 2026
CVE-2026-71497MEDIUM4.7
  • Java logoJava
  • jsoup
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management