PT-2026-95703 · Cotonti · Cotonti

CVE-2026-93872

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cotonti version 1.0.0
Description In the comments plugin EditAction, the software passes the base64-decoded cb parameter to the unserialize() function without restricting allowed classes. This allows registered users with comment write permissions to instantiate arbitrary PHP objects, which may lead to file write or remote code execution through gadget chains (sequences of existing code fragments that can be leveraged to achieve an unintended goal).
Recommendations Update Cotonti version 1.0.0 to a version where the unserialize() function in the comments plugin EditAction is properly restricted or replaced. As a temporary mitigation, restrict comment write permissions for registered users.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93872

Affected Products

Cotonti