PT-2026-95226 · Hgiga · Oaklouds
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OAKlouds (affected versions not specified)
Description
OAKlouds developed by HGiga contains an insecure deserialization flaw. This issue allows unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content. Insecure deserialization occurs when untrusted data is used to abuse the logic of an application to execute unexpected commands or code.
Recommendations
Update to the corrected version.
Limit external exposure of the service.
Review logs for anomalous access and search for indicators of compromise.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oaklouds