OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104905

HIGH · CVSS 8.1 EPSS 0.51% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Authenticated attackers can exploit a PHP object injection vulnerability in FacturaScripts prior to version 2026.7, specifically in the WidgetSelect::processFormData() function. By submitting crafted serialized data, they can invoke the __destruct() method of an XLSXWriter object, leading to arbitrary file deletion and potential denial of service. Organizations using affected versions should prioritize patching to mitigate the risk of application compromise and data loss.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104905
Severity
HIGH
CVSS
8.1
EPSS
0.51%

Original NVD Description

FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specified files such as config.php or backup data, resulting in denial of service and potential application reinstall hijack.