{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ab2evolutionb2evolution6.7.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:b2evolution:b2evolution:6.7.8:*:*:*:*:*:*:*","cpe:2.3:a:b2evolution:b2evolution:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:b2evolution:b2evolution:6.7.6:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2016-8901"},{"cvss":8.1,"id":"CVE-2026-76834"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["b2evolution CMS (6.7.8-7.2.5)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","deserialization","rce"],"_cs_type":"advisory","_cs_vendors":["b2evolution"],"content_html":"\u003cp\u003eb2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901, leaving the application susceptible to insecure deserialization attacks. The vulnerability resides in the param_check_serialized_array() function, which fails to correctly reject serialized PHP payloads containing negative integer array keys. An unauthenticated attacker can exploit this flaw by sending a crafted, malicious serialized PHP object via a POST request to the htsrv/call_plugin.php endpoint.\u003c/p\u003e\n\u003cp\u003eIf the application reaches the unserialize() function with this crafted payload, it results in the instantiation of arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) gadget chain is present within the application environment or associated plugins, the attacker can leverage this instantiation to achieve remote code execution. This vulnerability represents a significant security risk for organizations running affected versions of b2evolution, as it allows for unauthorized interaction with the application backend without prior authentication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-76834 allows unauthenticated attackers to instantiate arbitrary PHP objects, which can lead to remote code execution when combined with appropriate gadget chains. This may result in full system compromise, data exfiltration, or unauthorized modification of the content management system. The vulnerability affects all users of b2evolution CMS versions 6.7.8 through 7.2.5.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade b2evolution CMS to a version beyond 7.2.5 that resolves the incomplete validation logic for CVE-2026-76834.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to inspect POST requests directed at /htsrv/call_plugin.php for serialized PHP objects (strings starting with 'a:' or 'O:') that contain negative integer array keys.\u003c/li\u003e\n\u003cli\u003eAudit existing plugins for the presence of dangerous magic methods (e.g., __destruct, __wakeup) that could serve as POP gadgets for insecure deserialization.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T17:58:51Z","date_published":"2026-09-17T17:58:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-b2evolution-deserialization/","summary":"b2evolution CMS versions 6.7.8 through 7.2.5 are vulnerable to insecure deserialization via improper validation of serialized objects containing negative integer array keys.","title":"Unauthenticated Insecure Deserialization in b2evolution CMS","url":"https://feed.craftedsignal.io/briefs/2026-09-b2evolution-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:b2evolution:b2evolution:6.7.8:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}