CVE Explorer
CVE-2026-11860
Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. This allows attackers to tamper with serialized payloads in transit and inject malicious objects. Because deserialization is performed without proper validation or class restrictions, crafted payloads can trigger dangerous magic methods (e.g., __wakeup() and __destruct()) and leverage gadget chains, resulting in arbitrary code execution. Exploitation is triggered automatically whe
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-94","description":"CWE-94 Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Quick.CMS","vendor":"OpenSolution","versions":[{"lessThanOrEqual":"6.8","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"ADJACENT","baseScore":7.5,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-94","description":"CWE-94 Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2026/06/CVE-2026-11860/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/references/0
{"tags":["product"],"url":"https://opensolution.org/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f504adbab9cd68063f41680c8c29bb6675b0084ca20001c2350a7835c9426156 · sha256:723c49c5e4ef72ba… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.