Remote Event Queue Endpoint Deserialization Vulnerability in Open-Web-Analytics
CVE-2026-97865

6.9MEDIUM

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-97865?

A security flaw in Open-Web-Analytics versions up to 1.8.1 allows remote attackers to manipulate the Remote Event Queue Endpoint through the Event::loadFromArray function in the queue.php file, enabling deserialization attacks. Users are advised to upgrade to version 1.8.2, which includes a patch addressing this vulnerability. The specific update has been documented and made available for implementation.

Affected Version(s)

Open-Web-Analytics 1.8.0

Open-Web-Analytics 1.8.1

Open-Web-Analytics 1.8.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Customeres (VulDB User)
.