openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runtime.exec for arbitrary command execution.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
openEQUELLA is an open-source digital repository and learning object management system widely used in educational institutions and enterprises for content management. CVE-2026-94109 exposes a critical remote code execution vulnerability affecting versions before 2026.1.0. The flaw stems from an unsandboxed TemplateClassResolver configuration in FreeMarker template compilation, allowing authenticated attackers to inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates. By instantiating dangerous classes like freemarker.template.utility.Execute, attackers can invoke Runtime.exec() for arbitrary command execution. This vulnerability matters because it requires only authentication (not zero-day privilege escalation), making it a significant risk for any organization running vulnerable versions. Educational institutions, content repositories, and enterprises managing sensitive digital assets face potential data exfiltration, system compromise, and lateral movement threats.
Casky.ai's 754 security skills mapped to MITRE ATT&CK would identify this attack pattern through detection of several key techniques: Command and Scripting Interpreter (T1059) execution following template injection payloads, Code Injection (T1059.007) patterns in template expressions, and Exploitation for Privilege Escalation (T1190) when attackers escalate from authenticated user to system-level command execution. Practitioners using Casky would observe findings highlighting suspicious FreeMarker template syntax in collection summaries and dashboard configuration inputs, anomalous Runtime.exec() instantiation attempts in application logs, and unauthorized system commands spawned from the application process. The platform's extended reasoning would correlate template injection indicators with subsequent process execution, helping security teams distinguish between legitimate templating and malicious payload delivery—critical for rapid threat hunting and containment in production environments.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-94109. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation