← Back to CVE List
CVE-2026-76834NVD
Vulnerability Summary
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
CVSS v4.0 Base Metrics — Score 9.2 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 8.1 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- b2evolution b2evolution CMS >= 6.7.8 and <= 7.2.5
- b2evolution b2evolution CMS 7.2.5
External References
- https://gist.github.com/axg11/3e29501c33f6e1e05ac2a00107afd64e
- https://github.com/b2evolution/b2evolution/blob/7.2.5/inc/_core/_param.funcs.php#L2860
- https://github.com/b2evolution/b2evolution/blob/7.2.5/htsrv/call_plugin.php#L49
- https://github.com/b2evolution/b2evolution/commit/25c21cf9cc4261324001f9039509710b37ee2c4d
- https://github.com/b2evolution/b2evolution/commit/999b5ad1d59760d7e450ceb541f55432fc74cd27
- https://github.com/b2evolution/b2evolution/commit/335abf09bcea61717bd00bc1e3889f8100ebd1bb
- https://b2evolution.net/news/2022/03/26/2022-update-eol
- https://github.com/b2evolution/b2evolution
- https://www.vulncheck.com/advisories/b2evolution-cms-6.7.8-through-7.2.5-object-injection-via-negative-integer-array-key