CRITICAL 9.8 CVE-2026-62077 Published 10 Oct 2026

Avala PHP Object Injection Vulnerability

Worried this affects your website?

Avala versions 1.1.4 and earlier are affected by an unauthenticated PHP Object Injection vulnerability.

The flaw can be exploited without authentication.

  • Affected versions: Avala <= 1.1.4
  • Authentication required: None

Reference: CVE-2026-62077 on NVD

← Back to Security News