Deserialization Vulnerability in Pachno 1.0.6 by Pachno
CVE-2026-40044
9.3CRITICAL
What is CVE-2026-40044?
Pachno version 1.0.6 is susceptible to a deserialization vulnerability, allowing attackers without authentication to execute arbitrary code. This occurs when malicious serialized objects are injected into cache files that can be accessed due to the world-writable permissions. The vulnerable cache files are named predictably, leading to their unserialization during the framework's bootstrap process prior to any authentication, effectively enabling unauthorized code execution.
Affected Version(s)
Pachno 1.0.6
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
