Description
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
Published: 2026-09-17
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an object injection flaw that permits an unauthenticated attacker to embed serialized PHP objects containing negative integer array keys into a POST request sent to htsrv/call_plugin.php. These payloads bypass the param_check_serialized_array() safeguard, reach the unserialize() routine, and instantiate arbitrary PHP objects. Because the attacker can set object properties at will, the flaw can lead to remote code execution if a suitable POSt gadget chain exists. The weakness is classified as CWE-502.

Affected Systems

The affected product is b2evolution CMS, versions 6.7.8 through 7.2.5. All releases in this range lack the necessary check to reject negative integer array keys, so any site running these versions is vulnerable.

Risk and Exploitability

The CVSS score of 9.2 places this flaw in the critical severity range. EPSS information is not available, so the current exploitation probability cannot be quantified. The attack vector is likely an unauthenticated HTTP POST to htsrv/call_plugin.php, a publicly reachable endpoint, which indicates a low barrier to exploitation. Although the vulnerability is not listed in CISA’s KEV catalog, its potential for arbitrary code execution if a gadget chain can be assembled remains high.

Generated by OpenCVE AI on September 17, 2026 at 21:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch, which updates b2evolution CMS to a version beyond 7.2.5 where the negative integer array key check is fully implemented.
  • If an immediate patch is unavailable, reduce the exploitation surface by disabling the call_plugin.php endpoint or limiting its access to trusted IP addresses and ensuring that plugin calls cannot be initiated from unauthenticated requests.
  • Add a defensive filter to reject any serialized payloads that contain negative integer array keys before they reach the unserialize() function, thereby blocking the injection path.

Generated by OpenCVE AI on September 17, 2026 at 21:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
Title b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key
First Time appeared B2evolution
B2evolution b2evolution Cms
Weaknesses CWE-502
CPEs cpe:2.3:a:b2evolution:b2evolution_cms:*:*:*:*:*:*:*:*
Vendors & Products B2evolution
B2evolution b2evolution Cms
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

B2evolution B2evolution Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T18:04:44.762Z

Reserved: 2026-08-19T20:34:00.154Z

Link: CVE-2026-76834

cve-icon Vulnrichment

Updated: 2026-09-18T18:04:41.161Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T16:17:42.270

Modified: 2026-09-23T17:17:47.930

Link: CVE-2026-76834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:36:53Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data