
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2898 is a deserialization vulnerability in funadmin up to version 7.1.0-rc4, affecting the getMember function in app/common/service/AuthCloudService.php at the Backend Endpoint. The vulnerability was published on February 22, 2026, and public exploit code became available shortly after on February 24, 2026. Affected versions include all funadmin releases up to and including 7.1.0-rc4 (rc1, rc2, rc3, rc4, and all prior versions). It carries a CVSS v3.1 base score of 6.5 (Medium), though the vendor has not responded to disclosure attempts (Feedly, VulDB).
The root cause is improper input validation (CWE-20) combined with deserialization of untrusted data (CWE-502) in the getMember function of AuthCloudService.php. An attacker can manipulate the cloud_account parameter submitted to the Backend Endpoint to inject a crafted serialized payload, which the application deserializes without adequate sanitization. Exploitation requires the attacker to be authenticated with low privileges and requires some degree of user interaction (passive). Public proof-of-concept code is available on GitHub, demonstrating the deserialization attack path (Feedly, PoC GitHub).
Successful exploitation allows an authenticated attacker to achieve remote code execution on the affected funadmin server by manipulating serialized objects, potentially compromising the confidentiality, integrity, and availability of the system. The CVSS v3.1 scoring reflects a high integrity impact with no confidentiality or availability impact in the base score, though real-world exploitation of deserialization flaws can lead to broader system compromise including data exfiltration and persistent access. The scope is limited to the affected funadmin instance, but lateral movement within the hosting environment is possible if the server has network access to internal resources (Feedly).
Multiple public proof-of-concept exploits are available on GitHub, published on February 24, 2026, increasing the practical risk of exploitation (PoC GitHub, CVE Issues). The CVSS v4.0 exploit maturity is rated as PROOF_OF_CONCEPT. The EPSS score is approximately 0.044%, indicating a currently low but non-negligible probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (Feedly).
app/common/service/AuthCloudService.php.getMember function. Reference the public PoC at https://github.com/aykhan32/CVE-2026-2898-FunAdmin-Deserialization for payload structure.cloud_account parameter.getMember function deserializes the untrusted cloud_account value without proper validation, executing the attacker-controlled payload.AuthCloudService.php or the getMember function with anomalous cloud_account parameter values; outbound connections from the funadmin server to unknown external IPs.app/common/service/AuthCloudService.php with large or encoded cloud_account parameter values; PHP deserialization errors or warnings in application logs.bash, curl, wget, python, nc); unexpected cron jobs or scheduled tasks created under the web server user account.No official patch is currently available, as the vendor has not responded to disclosure. As immediate mitigations, restrict network access to the funadmin Backend Endpoint, particularly from untrusted or external networks, using firewall rules or WAF policies. Implement strict input validation and consider disabling or removing the getMember function in AuthCloudService.php if it is not critical to operations. Monitor authentication logs for suspicious low-privilege access attempts and apply application-level controls to sanitize or restrict the cloud_account parameter. Organizations should evaluate replacing funadmin with a supported alternative if the vendor remains unresponsive (Feedly).
Red Hat has tracked this CVE in their security advisory database, though funadmin is not a Red Hat product. The vulnerability was reported via VulDB and picked up by multiple vulnerability aggregators including Vulners, CIRCL, and INCIBE-CERT shortly after publication. The vendor was contacted prior to public disclosure but did not respond, resulting in a full public disclosure with exploit code available (Red Hat CVE, VulDB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."