PT-2026-94367 · Git+1 · B2Evolution+1

·

CVE-2026-76834

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions b2evolution CMS versions 6.7.8 through 7.2.5
Description An incomplete fix in the param check serialized array() function fails to reject payloads containing negative integer array keys. Unauthenticated attackers can send crafted serialized PHP objects via POST requests to the 'htsrv/call plugin.php' endpoint. This allows the bypass of validation to reach the unserialize() function, enabling the instantiation of arbitrary PHP objects with attacker-controlled properties. This may lead to remote code execution if suitable POP (Property Oriented Programming) gadget chains are present.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76834

Affected Products

B2Evolution
B2Evolution Cms