CVE-2026-2898: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-2898 is a deserialization vulnerability in funadmin up to version 7.1.0-rc4, affecting the getMember function in app/common/service/AuthCloudService.php at the Backend Endpoint. The vulnerability was published on February 22, 2026, and public exploit code became available shortly after on February 24, 2026. Affected versions include all funadmin releases up to and including 7.1.0-rc4 (rc1, rc2, rc3, rc4, and all prior versions). It carries a CVSS v3.1 base score of 6.5 (Medium), though the vendor has not responded to disclosure attempts (Feedly, VulDB).

Technical details

The root cause is improper input validation (CWE-20) combined with deserialization of untrusted data (CWE-502) in the getMember function of AuthCloudService.php. An attacker can manipulate the cloud_account parameter submitted to the Backend Endpoint to inject a crafted serialized payload, which the application deserializes without adequate sanitization. Exploitation requires the attacker to be authenticated with low privileges and requires some degree of user interaction (passive). Public proof-of-concept code is available on GitHub, demonstrating the deserialization attack path (Feedly, PoC GitHub).

Impact

Successful exploitation allows an authenticated attacker to achieve remote code execution on the affected funadmin server by manipulating serialized objects, potentially compromising the confidentiality, integrity, and availability of the system. The CVSS v3.1 scoring reflects a high integrity impact with no confidentiality or availability impact in the base score, though real-world exploitation of deserialization flaws can lead to broader system compromise including data exfiltration and persistent access. The scope is limited to the affected funadmin instance, but lateral movement within the hosting environment is possible if the server has network access to internal resources (Feedly).

Exploitability

Multiple public proof-of-concept exploits are available on GitHub, published on February 24, 2026, increasing the practical risk of exploitation (PoC GitHub, CVE Issues). The CVSS v4.0 exploit maturity is rated as PROOF_OF_CONCEPT. The EPSS score is approximately 0.044%, indicating a currently low but non-negligible probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing funadmin instances running versions up to 7.1.0-rc4 using web search, Shodan, or Censys, targeting the Backend Endpoint at app/common/service/AuthCloudService.php.
  2. Authentication: Obtain low-privilege credentials to the funadmin backend (e.g., via credential stuffing, phishing, or default credentials), as the vulnerability requires an authenticated session.
  3. Craft malicious payload: Construct a serialized PHP object payload designed to execute arbitrary commands when deserialized by the getMember function. Reference the public PoC at https://github.com/aykhan32/CVE-2026-2898-FunAdmin-Deserialization for payload structure.
  4. Submit payload: Send an HTTP request to the vulnerable Backend Endpoint, injecting the crafted serialized object into the cloud_account parameter.
  5. Trigger deserialization: The server-side getMember function deserializes the untrusted cloud_account value without proper validation, executing the attacker-controlled payload.
  6. Achieve objective: Depending on the payload, the attacker may achieve remote code execution, establish a reverse shell, exfiltrate data, or create persistent access on the server (PoC GitHub, Feedly).

Indicators of compromise

  • Network: Unusual or unexpected HTTP POST/GET requests to the Backend Endpoint involving AuthCloudService.php or the getMember function with anomalous cloud_account parameter values; outbound connections from the funadmin server to unknown external IPs.
  • Logs: Web server or application logs showing requests to app/common/service/AuthCloudService.php with large or encoded cloud_account parameter values; PHP deserialization errors or warnings in application logs.
  • File System: Unexpected new PHP files (web shells) in the funadmin application directory; modification timestamps on core files inconsistent with legitimate updates.
  • Process: Unusual child processes spawned by the PHP/web server process (e.g., bash, curl, wget, python, nc); unexpected cron jobs or scheduled tasks created under the web server user account.

Mitigation and workarounds

No official patch is currently available, as the vendor has not responded to disclosure. As immediate mitigations, restrict network access to the funadmin Backend Endpoint, particularly from untrusted or external networks, using firewall rules or WAF policies. Implement strict input validation and consider disabling or removing the getMember function in AuthCloudService.php if it is not critical to operations. Monitor authentication logs for suspicious low-privilege access attempts and apply application-level controls to sanitize or restrict the cloud_account parameter. Organizations should evaluate replacing funadmin with a supported alternative if the vendor remains unresponsive (Feedly).

Community reactions

Red Hat has tracked this CVE in their security advisory database, though funadmin is not a Red Hat product. The vulnerability was reported via VulDB and picked up by multiple vulnerability aggregators including Vulners, CIRCL, and INCIBE-CERT shortly after publication. The vendor was contacted prior to public disclosure but did not respond, resulting in a full public disclosure with exploit code available (Red Hat CVE, VulDB).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management