PT-2026-91278 · Unknown · October Cms
CVE-2026-49400
·
Published
2026-09-13
·
Updated
2026-09-16
CVSS v2.0
3.6
Low
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
October CMS versions prior to 3.7.17
October CMS versions prior to 4.2.21
Description
The backend
SessionMaker trait stores widget session state using base64(serialize(...)) and processes it with the unserialize() function without an allowed classes restriction. This can lead to PHP object injection, allowing the instantiation of arbitrary classes and the execution of PHP gadget chains, potentially resulting in arbitrary code execution as the web server user. This issue specifically affects installations where cms.safe mode is enabled, a feature used for demo installations or multi-tenant scenarios where untrusted users have access to the CMS markup editor. Exploitation requires a path to write attacker-controlled bytes to a widget.* session key and the presence of a suitable PHP gadget chain within the installed dependencies.Recommendations
Update to version 3.7.17 or later.
Update to version 4.2.21 or later.
Restrict CMS markup editing access to fully trusted administrators only.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
October Cms