Description
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Published: 2026-09-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an insecure deserialization flaw that allows unauthenticated remote attackers to execute arbitrary code on the servers hosting OAKlouds. By sending maliciously crafted serialized payloads, an attacker can take full control of the system, enabling persistence and data theft. This weakness is classified as CWE‑502, indicating unsafe handling of serialized data.

Affected Systems

HGiga’s OAKlouds custom_page modules version 2.0, 3.0 and 4.0 are affected. All releases prior to 26 of each major version lack the necessary protection. The vendor recommends updating to version 26 or later to remediate the issue.

Risk and Exploitability

The CVSS score of 9.3 signifies critical severity. The EPSS score of less than 1 % suggests that exploitation is currently unlikely, and the vulnerability is not in the CISA KEV catalog. The attack vector is inferred to be remote and unauthenticated, relying on the deserialization endpoint to process attacker‑supplied data, which permits remote code execution if the server accepts the payload. Because the flaw can be triggered without authentication, the potential impact is system‑wide compromise should an attacker be able to reach the affected endpoint.

Generated by OpenCVE AI on September 19, 2026 at 21:00 UTC.

Remediation

Vendor Solution

Update OAKlouds-custom_page-2.0 version 26 or later Update OAKlouds-custom_page-3.0 version 26 or later Update OAKlouds-custom_page-4.0 version 26 or later


OpenCVE Recommended Actions

  • Update OAKlouds-custom_page-2.0, -3.0, and -4.0 to version 26 or later.
  • If a patch cannot be applied immediately, block or restrict inbound traffic to the deserialization endpoint or disable the feature that accepts serialized input.
  • Apply strict input validation to reject non‑conforming serialized data before deserialization to prevent the payload from being executed.

Generated by OpenCVE AI on September 19, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Hgiga
Hgiga oaklouds-custom Page-2.0
Hgiga oaklouds-custom Page-3.0
Hgiga oaklouds-custom Page-4.0
Vendors & Products Hgiga
Hgiga oaklouds-custom Page-2.0
Hgiga oaklouds-custom Page-3.0
Hgiga oaklouds-custom Page-4.0

Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Title HGiga|OAKlouds - Insecure Deserialization
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hgiga Oaklouds-custom Page-2.0 Oaklouds-custom Page-3.0 Oaklouds-custom Page-4.0
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-18T14:31:42.129Z

Reserved: 2026-09-18T01:58:58.069Z

Link: CVE-2026-93467

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:34.183Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T03:16:33.753

Modified: 2026-09-18T19:15:11.780

Link: CVE-2026-93467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:00:09Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data