Sceawere
Vulnerability Detail
CVE-2026-104747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated PHP Object Injection in Haaken
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 16h ago
- Vendor
- Edge-Themes
- Product
- Haaken
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Unauthenticated PHP Object Injection in Haaken <= 1.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-06T09:17:39.643Z",
"pubdate": "2026-10-06T09:17:39.643Z",
"executiveSummary": "A critical PHP Object Injection vulnerability exists in Haaken versions 1.5 and below. This security flaw allows unauthenticated remote attackers to inject serialized PHP objects into the application, potentially leading to Remote Code Execution (RCE), unauthorized data manipulation, or denial-of-service conditions.\nThe vulnerability arises from insecure deserialization practices where user-supplied input is processed by PHP's unserialize() function without sufficient validation or integrity checks. Because the vulnerability is exploitable without prior authentication, it poses a high risk to the confidentiality, integrity, and availability of the affected system.\nSuccessful exploitation depends on the presence of 'gadget chains' within the application or its bundled libraries—sequences of method calls that perform dangerous actions (such as file system operations or command execution) when a malicious object is instantiated.\nOrganizations using Haaken <= 1.5 are exposed to total system compromise if an attacker can deliver a crafted serialized payload to a vulnerable endpoint. Immediate remediation is required to prevent unauthorized access and potential persistent compromise of the hosting server.",
"technicalDetails": "The vulnerability is rooted in the improper handling of untrusted user input passed to the unserialize() function in Haaken versions 1.5 and below. In PHP, the unserialize() function reconstructs stored values into original PHP data structures; however, if the input is attacker-controlled, it can lead to the instantiation of arbitrary classes present in the application's scope.\nAttack flow typically begins with the identification of an entry point where the application accepts serialized data, often via HTTP POST parameters, cookies, or headers. When the application calls unserialize() on this tainted data, PHP initiates the magic methods of the injected objects. Specifically, the __wakeup() or __destruct() methods are triggered automatically during object restoration and destruction.\nIf an attacker successfully identifies a 'gadget chain'—classes within the application codebase that implement these magic methods to perform actions like file inclusion, arbitrary file writes, or arbitrary command execution—they can craft a malicious serialized payload. By chaining these objects, the attacker directs the execution flow of the application to execute arbitrary code with the privileges of the web server process.\nThis vulnerability is classified as unauthenticated because the entry point for the serialized input does not enforce session validation or authorization checks prior to reaching the vulnerable deserialization sink. Consequently, the attack surface is exposed to any network-capable entity able to reach the application's HTTP interface.\nThe impact of this injection is severe. Beyond simple application logic bypass, an attacker can achieve complete Remote Code Execution (RCE) by leveraging gadgets that interact with sensitive system functions. Post-exploitation activities may include the deployment of web shells, pivot operations within the internal network, or full exfiltration of the application database and configuration files. Because PHP's deserialization process is inherently difficult to secure once user input is accepted, the vulnerability represents a foundational security failure in the way Haaken handles incoming data streams."
}