CRITICAL
9.8 CVE-2026-62077 Published 10 Oct 2026
Avala PHP Object Injection Vulnerability
Worried this affects your website?
Avala versions 1.1.4 and earlier are affected by an unauthenticated PHP Object Injection vulnerability.
The flaw can be exploited without authentication.
- Affected versions: Avala <= 1.1.4
- Authentication required: None
Reference: CVE-2026-62077 on NVD
← Back to Security News