OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94678

HIGH · CVSS 8.8 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects versions of Go Live Update Urls up to and including 7.0.8, allowing for PHP Object Injection due to improper handling of user input. This can lead to remote code execution, enabling attackers to manipulate the application and potentially compromise the underlying system. Organizations using these affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-94678
Severity
HIGH
CVSS
8.8
EPSS
0.38%

Original NVD Description

Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.