OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96344

HIGH · CVSS 7.2 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects versions of the eCommerce Product Catalog up to 3.6.0, where a custom role PHP Object Injection can be exploited. This could allow an attacker to execute arbitrary PHP code, potentially leading to unauthorized access or manipulation of sensitive data. Organizations using this software should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-96344
Severity
HIGH
CVSS
7.2
EPSS
0.37%

Original NVD Description

Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.