SB2026072467 - Deserialization of Untrusted Data in NukeViet
Published: July 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deserialization of Untrusted Data (CVE-ID: CVE-2026-61832)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in extension store management handlers when processing an unverified HTTP response body. A remote attacker can substitute the response body with a crafted PHP serialized payload to execute arbitrary code.
Exploitation requires a privileged administrator to perform a store action such as opening the store list, install, update, or detail, and requires the ability to intercept or alter outbound traffic to the store endpoint.
Remediation
Install update from vendor's website.