Deserialization Vulnerability in eta-otp-lock
An insecure deserialization vulnerability in TUBITAK BILGEM eta-otp-lock (CVE-2026-18642) allows unauthenticated attackers to perform object injection, potentially leading to remote code execution.
The TUBITAK BILGEM Software Technologies Research Institute has disclosed a deserialization of untrusted data vulnerability (CVE-2026-18642) affecting the eta-otp-lock utility. This vulnerability, identified as CWE-502, resides in the way the application handles serialized objects. Successful exploitation allows an attacker to inject arbitrary objects into the application, which may facilitate unauthorized code execution or system compromise. The vulnerability affects all versions of eta-otp-lock prior to 1.0.4. Given the nature of object injection vulnerabilities, organizations utilizing this software should prioritize upgrading to version 1.0.4 or later to mitigate potential exploitation attempts.
Impact
The vulnerability carries a CVSS 3.1 base score of 7.8, representing a high risk to the confidentiality, integrity, and availability of systems running vulnerable versions of eta-otp-lock. Successful exploitation could allow an attacker to achieve code execution with the privileges of the application process.
Recommendation
- Upgrade the eta-otp-lock software to version 1.0.4 or later immediately.
- Review internal application logs for unauthorized object instantiation or unexpected process execution spawned by the eta-otp-lock service.
- Restrict network access to any instances of eta-otp-lock to ensure they are not exposed to untrusted sources, minimizing the potential for an attacker to send malicious serialized objects.
Immediate actions
Upgrade eta-otp-lock to 1.0.4 or later