CVE-2026-29782 is a high-severity PHP object injection vulnerability (CWE-502) affecting OpenSTAManager versions prior to 2.10.2. Rated 7.2 High (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), this flaw in the unauthenticated oauth2.php endpoint allows a remote attacker to achieve complete compromise of confidentiality, integrity, and availability. It occurs when the application calls unserialize() on attacker-controlled input without class restrictions, potentially leading to remote code execution. There is currently no known active exploitation (KEV: No) or public exploit code, and community discussion is minimal, though it is listed on a "Hot List."
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.10.2CPE matchmatch criteria | cpe:2.3:a:devcode:openstamanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.