CVE-2026-76834

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.

  • Published Sep 17, 2026
  • CVSS 9.2 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-76834 at the National Vulnerability Database