<Vulnerability name="CVE-2026-15538">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-13T06:00:11</PublicDate>
    <Bugzilla id="2499590" url="https://bugzilla.redhat.com/show_bug.cgi?id=2499590" xml:lang="en:us">
primereact: PrimeReact: Remote attacker can modify object prototype attributes
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-915</CWE>
    <Details xml:lang="en:us" source="Mitre">
A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet. This vulnerability only affects products that are no longer supported by the maintainer.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in PrimeFaces PrimeReact. A remote attacker can exploit a weakness in the ObjectUtils.mutateFieldData function within the component API. This allows for the improper modification of object prototype attributes, potentially leading to unexpected behavior or further attacks. This vulnerability affects products that are no longer supported by the maintainer.
    </Details>
    <Statement xml:lang="en:us">
This Moderate flaw in PrimeFaces PrimeReact allows a remote attacker to modify object prototype attributes through the `ObjectUtils.mutateFieldData` function. This could lead to unexpected application behavior or further attacks. Red Hat Enterprise Linux AI components are affected by this vulnerability.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhelai3/bootc-cuda-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhelai3/bootc-gaudi-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhelai3/bootc-rocm-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:enterprise_linux_ai:3">
        <ProductName>Red Hat Enterprise Linux AI (RHEL AI) 3</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhelai3/disk-image-cuda-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-15538
https://nvd.nist.gov/vuln/detail/CVE-2026-15538
https://github.com/Mantle-UI/mantle-ui/issues/50
https://github.com/primefaces/primereact/
https://github.com/primefaces/primereact/issues/8553
https://vuldb.com/cve/CVE-2026-15538
https://vuldb.com/submit/855024
https://vuldb.com/vuln/377888
https://vuldb.com/vuln/377888/cti
    </References>
</Vulnerability>