Deserialization Vulnerability in Pachno 1.0.6 by Pachno
CVE-2026-40044

9.3CRITICAL

Key Information:

Vendor

Pancho

Status
Vendor
CVE Published:
13 April 2026

What is CVE-2026-40044?

Pachno version 1.0.6 is susceptible to a deserialization vulnerability, allowing attackers without authentication to execute arbitrary code. This occurs when malicious serialized objects are injected into cache files that can be accessed due to the world-writable permissions. The vulnerable cache files are named predictably, leading to their unserialization during the framework's bootstrap process prior to any authentication, effectively enabling unauthorized code execution.

Affected Version(s)

Pachno 1.0.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LiquidWorm as Gjoko Krstic of Zero Science Lab
.