Sceawere
Vulnerability Detail
CVE-2026-62050UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Splendour Unauthenticated PHP Object Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 5h ago
- Vendor
- ThemeREX
- Product
- Splendour
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated PHP Object Injection in Splendour <= 1.23 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-10T20:16:40.260Z",
"pubdate": "2026-10-10T20:16:40.260Z",
"executiveSummary": "A critical vulnerability exists in Splendour versions 1.23 and below, identified as an unauthenticated PHP Object Injection flaw.\nThis vulnerability stems from the insecure deserialization of untrusted data provided by an attacker, which can lead to Remote Code Execution (RCE) or arbitrary file deletion within the application environment.\nThe flaw is particularly dangerous because it requires no authentication, allowing any remote, unauthenticated user to interact with the vulnerable endpoint.\nSuccessful exploitation grants the attacker the ability to execute arbitrary PHP code, potentially leading to a complete compromise of the host server.\nThe risk is categorized as critical due to the ease of exploitation, the lack of required privileges, and the severity of the potential impact on system confidentiality, integrity, and availability.",
"technicalDetails": "The vulnerability resides in the way Splendour handles user-supplied data that is passed directly to the PHP unserialize() function without adequate validation or sanitization.\nPHP Object Injection occurs when an attacker supplies a crafted serialized object string to an application that expects to deserialize data, effectively manipulating the application's internal state.\nWhen the vulnerable component processes this maliciously crafted input, PHP instantiates objects of arbitrary classes available in the application scope.\nIf the application includes 'magic methods'—specifically __destruct(), __wakeup(), or __toString()—the attacker can trigger these methods during the deserialization process to execute arbitrary code or manipulate object properties.\nThe attack flow proceeds as follows: First, the attacker identifies an input vector, such as a cookie, GET parameter, or POST body, that is processed by the application's deserialization logic. Second, the attacker utilizes POP (Property Oriented Programming) chains—a sequence of gadgets found within the application's codebase—to redirect the execution flow.\nBy chaining these gadgets, the attacker can leverage existing object properties to perform unauthorized actions. For example, if a gadget exists that interacts with the file system based on an object property, the attacker can manipulate the serialized object to force the application to read, write, or delete arbitrary files on the server.\nIn more severe scenarios, the attacker can use the injection to instantiate classes that facilitate command execution, such as those that interact with system shells or eval() functions.\nBecause this endpoint is reachable without authentication, the attack surface is exposed to the public internet. The payload behavior is limited only by the available classes within the Splendour application and the PHP environment. Once the payload is delivered, the execution occurs within the context of the web server process (e.g., www-data), granting the attacker the same permissions as the web server user.\nPost-exploitation impact includes full system compromise, data exfiltration, persistent backdoor installation, and the lateral movement of the attacker within the internal network infrastructure."
}