A vulnerability was found in Eclipse Mojarra up to 5.0. It has been rated as problematic. The affected element is the function
DefaultFaceletFactory of the component URL Handler. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-46581. The attack may be initiated remotely. There is no available exploit.