AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-28176

HIGH · CVSS 8.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated PHP Object Injection in Booking Activities versions up to 1.18.4, potentially enabling attackers to execute arbitrary code or manipulate application behavior. Organizations using affected versions should prioritize patching this issue due to its high severity and the risk of exploitation. Immediate action is recommended for those managing web applications that rely on this software to mitigate potential security breaches.

CVE
CVE-2026-28176
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.