CyberRota Analysis
AI-GeneratedUnauthenticated PHP Object Injection vulnerabilities in Agora versions up to 1.9 allow attackers to exploit the application by injecting malicious objects, potentially leading to remote code execution and full system compromise. Organizations using affected versions should prioritize immediate patching or mitigation strategies, as the critical severity rating indicates a high risk of exploitation. This vulnerability poses a significant threat to any systems running the specified software, particularly in environments where security controls are lax.
CVE
CVE-2026-65578
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%
Original NVD Description
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.