PT-2026-52748 · Unknown · Buddyboss Platform

·

CVE-2026-56032

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buddyboss Platform versions prior to 3.0.5
Description PHP Object Injection occurs when an application deserializes untrusted data, allowing an attacker to manipulate the application logic or execute arbitrary code by injecting malicious objects into the Subscriber object.
Recommendations Update Buddyboss Platform to version 3.0.5 or later.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56032

Affected Products

Buddyboss Platform