CVE-2026-93467

9.8

HGiga · OAKlouds-custom_page

HGiga OAKlouds-custom_page is vulnerable to insecure deserialization, allowing unauthenticated remote attackers to execute arbitrary code via maliciously crafted serialized content.

Executive summary

A critical insecure deserialization vulnerability in HGiga OAKlouds-custom_page allows unauthenticated remote attackers to achieve full remote code execution on affected servers.

Vulnerability

The application fails to properly validate serialized data before deserialization, which allows unauthenticated remote attackers to inject malicious objects and trigger arbitrary code execution.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected server, leading to potential data exfiltration, system compromise, and significant operational disruption. Given the CVSS score of 9.8, this flaw represents a maximum severity risk that requires immediate attention to prevent unauthorized access to sensitive environments.

Remediation

Immediate Action: Update all instances of OAKlouds-custom_page (versions 2.0, 3.0, and 4.0) to version 26 or later immediately.

Proactive Monitoring: Review web server and application logs for suspicious serialized strings or unexpected system-level processes originating from the web application service account.

Compensating Controls: Deploy a Web Application Firewall with rules configured to inspect incoming traffic for serialized objects or common deserialization attack patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a severe risk to infrastructure integrity due to the lack of required authentication for exploitation. Security teams must prioritize patching all affected OAKlouds deployments to version 26 or higher to neutralize this threat. If immediate patching is not feasible, restrict network access to the vulnerable components to limit the potential attack surface until remediation is complete.

More HGiga CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources