Sceawere

Vulnerability Detail

CVE-2026-62051UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stargaze Unauthenticated PHP Object Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
5h ago
Vendor
ThemeREX
Product
Stargaze
Attack Type
CWE-502 Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated PHP Object Injection in Stargaze <= 1.10 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T20:16:40.387Z",
  "pubdate": "2026-10-10T20:16:40.387Z",
  "executiveSummary": "A critical vulnerability exists in Stargaze versions 1.10 and below, identified as an Unauthenticated PHP Object Injection flaw. This vulnerability allows remote, unauthenticated attackers to supply maliciously crafted serialized data to the application, which is subsequently processed by vulnerable deserialization functions.\nBy manipulating the object state during deserialization, an attacker can influence application logic, bypass security controls, or execute arbitrary code depending on the presence of available 'gadget chains' within the application's codebase or included libraries.\nThe risk is severe as it does not require authentication or elevated privileges, allowing for potential full system compromise, remote code execution, or unauthorized data access. The vulnerability exposes the application's internal object structure to manipulation, significantly impacting the confidentiality, integrity, and availability of the affected system. Organizations utilizing Stargaze are at high risk if their instance is exposed to the network, as the attack vector can be triggered via standard HTTP requests without prior interaction from a legitimate user.",
  "technicalDetails": "The vulnerability resides in the way Stargaze handles input data that is passed to PHP's unserialize() function or similar deserialization mechanisms. In PHP, the unserialize() function is inherently dangerous when processing untrusted user input, as it restores the state of an object, including its properties, and can trigger magic methods such as __wakeup(), __destruct(), or __toString() automatically.\nThe attack flow commences when an attacker identifies an input vector—such as a cookie, a URL parameter, or a POST field—that is directly passed to a vulnerable deserialization routine without prior validation or cryptographic signing. By crafting a serialized PHP payload, an attacker can define the class type of the object and the values assigned to its properties.\nUpon deserialization, if the application contains 'gadget chains'—a sequence of existing code components that, when linked together via object property manipulation, perform an unintended action—the attacker can achieve remote code execution (RCE). For example, if a class exists within the application scope that performs file operations, database queries, or system commands within its __destruct() magic method, the attacker can instantiate this object with malicious values to trigger these operations upon the script's termination.\nBecause this vulnerability is unauthenticated, the exploitation requirement is minimal. The attacker simply needs to identify the entry point and ensure the serialized object corresponds to a class accessible within the PHP application's include path. This makes it a high-utility exploit for attackers aiming for persistent or immediate code execution. The impact of successful exploitation includes, but is not limited to, the ability to read or modify sensitive configuration files, establish unauthorized database connections, bypass authentication tokens, or achieve complete web server compromise by spawning reverse shells via injected commands.\nThe vulnerability affects Stargaze versions 1.10 and all prior versions. The root cause is the unsafe consumption of untrusted data in the deserialization process, which violates secure coding practices for handling serialized objects in web applications. Without adequate input filtering or the use of safer data interchange formats like JSON, the application remains susceptible to memory corruption, object state hijacking, and subsequent unauthorized command execution."
}
CVE-2026-62051: Stargaze Unauthenticated PHP Object Injection (CRITICAL Severity, CVSS: 9.8) | Sceawere