๐Ÿ” CVE Alert

CVE-2026-76834

HIGH 8.1

b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.

CWE CWE-502
Vendor b2evolution
Product b2evolution cms
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for b2evolution b2evolution cms

Be the first to know when new high vulnerabilities affecting b2evolution b2evolution cms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

b2evolution / b2evolution CMS
6.7.8 โ‰ค 7.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gist.github.com: https://gist.github.com/axg11/3e29501c33f6e1e05ac2a00107afd64e github.com: https://github.com/b2evolution/b2evolution/blob/7.2.5/inc/_core/_param.funcs.php#L2860 github.com: https://github.com/b2evolution/b2evolution/blob/7.2.5/htsrv/call_plugin.php#L49 github.com: https://github.com/b2evolution/b2evolution/commit/25c21cf9cc4261324001f9039509710b37ee2c4d github.com: https://github.com/b2evolution/b2evolution/commit/999b5ad1d59760d7e450ceb541f55432fc74cd27 github.com: https://github.com/b2evolution/b2evolution/commit/335abf09bcea61717bd00bc1e3889f8100ebd1bb b2evolution.net: https://b2evolution.net/news/2022/03/26/2022-update-eol github.com: https://github.com/b2evolution/b2evolution vulncheck.com: https://www.vulncheck.com/advisories/b2evolution-cms-6.7.8-through-7.2.5-object-injection-via-negative-integer-array-key

Credits

Adrian Gaitan VulnCheck