OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97865

HIGH · CVSS 7.3 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in Open-Web-Analytics versions up to 1.8.1 allows for remote deserialization attacks through the Event::loadFromArray function in the queue.php file. This flaw could be exploited by attackers to manipulate data, potentially leading to unauthorized actions within the application. Organizations using affected versions should prioritize upgrading to version 1.8.2 to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97865
Severity
HIGH
CVSS
7.3
EPSS
0.40%

Original NVD Description

A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The affected component should be upgraded.