SB2026072467 - Deserialization of Untrusted Data in NukeViet



SB2026072467 - Deserialization of Untrusted Data in NukeViet

Published: July 24, 2026

Security Bulletin ID SB2026072467
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Deserialization of Untrusted Data (CVE-ID: CVE-2026-61832)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in extension store management handlers when processing an unverified HTTP response body. A remote attacker can substitute the response body with a crafted PHP serialized payload to execute arbitrary code.

Exploitation requires a privileged administrator to perform a store action such as opening the store list, install, update, or detail, and requires the ability to intercept or alter outbound traffic to the store endpoint.


Remediation

Install update from vendor's website.