CVE-2026-97865
Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The patch is named 78c1222ec0e2119d84684032da1541120a2cdd23. The affected component should be upgraded.
| CWE | CWE-502 CWE-20 |
| Vendor | n/a |
| Product | open-web-analytics |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a open-web-analytics
Be the first to know when new high vulnerabilities affecting n/a open-web-analytics are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / Open-Web-Analytics
1.8.0 1.8.1
References
vuldb.com: https://vuldb.com/vuln/409882 vuldb.com: https://vuldb.com/vuln/409882/cti vuldb.com: https://vuldb.com/cve/CVE-2026-97865 vuldb.com: https://vuldb.com/submit/911108 github.com: https://github.com/Open-Web-Analytics/Open-Web-Analytics/issues/960 github.com: https://github.com/Open-Web-Analytics/Open-Web-Analytics/pull/967 github.com: https://github.com/Open-Web-Analytics/Open-Web-Analytics/commit/78c1222ec0e2119d84684032da1541120a2cdd23 github.com: https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.8.2 github.com: https://github.com/Open-Web-Analytics/Open-Web-Analytics/
Credits
๐ Customeres (VulDB User)