CVE-2026-3968 | AutohomeCorp frostmourne up to 1.0 Oracle Nashorn JavaScript Engine ExpressionRule.java scriptEngine.eval EXPRESSION code injection (EUVD-2026-11493)
A vulnerability was found in AutohomeCorp frostmourne up to 1.0 and classified as critical. This affects the function scriptEngine.eval of the file ExpressionRule.java of the component Oracle Nashorn JavaScript Engine. Such manipulation of the argument EXPRESSION leads to code injection.
This vulnerability is documented as CVE-2026-3968. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.