PHP Object Injection Vulnerability in Cypht by Cypht Team
CVE-2026-71981
8.7HIGH
What is CVE-2026-71981?
The Cypht platform prior to version 2.12.2 is susceptible to a PHP object injection vulnerability. This flaw allows authenticated attackers to execute arbitrary commands on the operating system by manipulating the back_query GET parameter during the logout process. By delivering a specially crafted PHP object graph, an attacker can inject a base64-encoded serialized payload that, upon decoding and execution, bypasses any validation measures, including allow-lists or signature checks. Consequently, this exposes the web server process to potential remote code execution exploits, enabling a malicious actor to execute commands and compromise server integrity.
Affected Version(s)
cypht 0
