Sceawere

Vulnerability Detail

CVE-2026-62050UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splendour Unauthenticated PHP Object Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
5h ago
Vendor
ThemeREX
Product
Splendour
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated PHP Object Injection in Splendour <= 1.23 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T20:16:40.260Z",
  "pubdate": "2026-10-10T20:16:40.260Z",
  "executiveSummary": "A critical vulnerability exists in Splendour versions 1.23 and below, identified as an unauthenticated PHP Object Injection flaw.\nThis vulnerability stems from the insecure deserialization of untrusted data provided by an attacker, which can lead to Remote Code Execution (RCE) or arbitrary file deletion within the application environment.\nThe flaw is particularly dangerous because it requires no authentication, allowing any remote, unauthenticated user to interact with the vulnerable endpoint.\nSuccessful exploitation grants the attacker the ability to execute arbitrary PHP code, potentially leading to a complete compromise of the host server.\nThe risk is categorized as critical due to the ease of exploitation, the lack of required privileges, and the severity of the potential impact on system confidentiality, integrity, and availability.",
  "technicalDetails": "The vulnerability resides in the way Splendour handles user-supplied data that is passed directly to the PHP unserialize() function without adequate validation or sanitization.\nPHP Object Injection occurs when an attacker supplies a crafted serialized object string to an application that expects to deserialize data, effectively manipulating the application's internal state.\nWhen the vulnerable component processes this maliciously crafted input, PHP instantiates objects of arbitrary classes available in the application scope.\nIf the application includes 'magic methods'—specifically __destruct(), __wakeup(), or __toString()—the attacker can trigger these methods during the deserialization process to execute arbitrary code or manipulate object properties.\nThe attack flow proceeds as follows: First, the attacker identifies an input vector, such as a cookie, GET parameter, or POST body, that is processed by the application's deserialization logic. Second, the attacker utilizes POP (Property Oriented Programming) chains—a sequence of gadgets found within the application's codebase—to redirect the execution flow.\nBy chaining these gadgets, the attacker can leverage existing object properties to perform unauthorized actions. For example, if a gadget exists that interacts with the file system based on an object property, the attacker can manipulate the serialized object to force the application to read, write, or delete arbitrary files on the server.\nIn more severe scenarios, the attacker can use the injection to instantiate classes that facilitate command execution, such as those that interact with system shells or eval() functions.\nBecause this endpoint is reachable without authentication, the attack surface is exposed to the public internet. The payload behavior is limited only by the available classes within the Splendour application and the PHP environment. Once the payload is delivered, the execution occurs within the context of the web server process (e.g., www-data), granting the attacker the same permissions as the web server user.\nPost-exploitation impact includes full system compromise, data exfiltration, persistent backdoor installation, and the lateral movement of the attacker within the internal network infrastructure."
}
CVE-2026-62050: Splendour Unauthenticated PHP Object Injection (CRITICAL Severity, CVSS: 9.8) | Sceawere