Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76834— b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key

Quick assessment

Affected
b2evolution b2evolution CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

B2 Evolution CMS 6.7.8 至 7.2.5 版本中存在对 CVE-2016-8901 的修复不完整问题。其中, 函数中的序列化数组对象检查无法拒绝包含负整数数组键的负载。 未认证的 attackers 可以通过向 发送精心构造的 POST 请求,提交由攻击者构造的已序列化 PHP 对象,从而绕过验证并到达 函数,实例化具有攻击者选定属性的任意 PHP 对象。如果存在合适的 POP 小工具链(POP gadget chains),则可能导致代码执行。

CVSS 8.1 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
b2evolution b2evolution CMS 6.7.8≤ 7.2.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76834

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
b2evolution CMS 6.7.8 through 7.2.5 Object Injection via Negative Integer Array Key
Source: CVE Program / CVE List V5
Vulnerability Description
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to htsrv/call_plugin.php that bypass validation and reach unserialize(), instantiating arbitrary PHP objects with attacker-chosen properties that may enable code execution if suitable POP gadget chains exist.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
b2evolution b2evolution CMS 6.7.8 ~ 7.2.5 -

II. Public POCs for CVE-2026-76834

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-76834

登录查看更多情报信息。

Patches & Fixes for CVE-2026-76834 (2)

Vendor Advisories for CVE-2026-76834 (1)

Proof of Concept for CVE-2026-76834 (1)

Vendor Pages for CVE-2026-76834 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76834

No comments yet


Leave a comment