{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/open-web-analytics/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:open_web_analytics:open_web_analytics:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-97865"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open-Web-Analytics (\u003c= 1.8.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","deserialization","rce"],"_cs_type":"advisory","_cs_vendors":["Open-Web-Analytics"],"content_html":"\u003cp\u003eA deserialization vulnerability exists in the Open-Web-Analytics (OWA) platform, specifically affecting versions 1.8.1 and earlier. The flaw resides within the \u003ccode\u003eEvent::loadFromArray\u003c/code\u003e function located in the \u003ccode\u003equeue.php\u003c/code\u003e file, which is part of the Remote Event Queue Endpoint component. An unauthenticated remote attacker can exploit this vulnerability by sending a maliciously crafted payload to the endpoint, leading to insecure deserialization. Successful exploitation allows for arbitrary code execution on the underlying web server. Defenders should immediately upgrade to OWA version 1.8.2 or apply the official patch (78c1222ec0e2119d84684032da1541120a2cdd23) to mitigate this high-severity risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full remote code execution on the web server hosting Open-Web-Analytics. This could lead to a complete system compromise, unauthorized access to sensitive analytics data, or the use of the server as a pivot point for lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Open-Web-Analytics to version 1.8.2 immediately to remediate CVE-2026-97865.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, apply the specific patch 78c1222ec0e2119d84684032da1541120a2cdd23.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at the \u003ccode\u003equeue.php\u003c/code\u003e endpoint that contain serialized object structures or unusual query parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T14:53:29Z","date_published":"2026-09-25T14:53:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-open-web-analytics-deserialization/","summary":"Open-Web-Analytics up to version 1.8.1 contains a remote deserialization vulnerability in the Remote Event Queue Endpoint that allows unauthenticated attackers to execute arbitrary code.","title":"Remote Code Execution via Deserialization in Open-Web-Analytics","url":"https://feed.craftedsignal.io/briefs/2026-09-open-web-analytics-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - Open-Web-Analytics","version":"https://jsonfeed.org/version/1.1"}