CVE-2026-33942: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33942 is an insecure deserialization vulnerability in the Saloon PHP library's AccessTokenAuthenticator class that can lead to object injection and remote code execution (RCE). It affects all versions of saloonphp/saloon prior to 4.0.0 and was disclosed on March 25–26, 2026. The vulnerability was discovered by researcher @HuajiHD and fixed by @JonPurvis. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 8.1 (High) (GitHub Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-502 (Deserialization of Untrusted Data). The vulnerable code in AccessTokenAuthenticator::unserialize() called PHP's native unserialize() with allowed_classes => true to restore OAuth token state from cache or storage, without restricting which classes could be instantiated. An attacker who can control the serialized string — for example, by overwriting a cached token file on disk or injecting data via another vulnerability — can supply a crafted serialized "gadget" object. When unserialize() processes this input, PHP instantiates the attacker-controlled object and automatically invokes its magic methods (__wakeup, __destruct, etc.), enabling object injection. In environments with common PHP dependencies such as Monolog, these gadget chains can be leveraged to achieve full RCE (GitHub Advisory, Github Advisory).

Impact

Successful exploitation can result in complete compromise of the affected system, with high impact to confidentiality, integrity, and availability. An attacker achieving RCE via a gadget chain can execute arbitrary commands as the web server process, exfiltrate sensitive data (including OAuth tokens and API credentials managed by Saloon), modify application data, or use the compromised host as a pivot point for lateral movement within the network. The attack requires no authentication and no user interaction, making it particularly dangerous for internet-facing applications that use Saloon's OAuth2 utilities (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.23% (46th percentile), indicating a relatively low near-term exploitation probability. The CVSSv4 exploit maturity is rated "Unreported." The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack vector is network-accessible with no privileges or user interaction required, and PHP deserialization gadget chains (e.g., via Monolog) are well-documented in the security community, lowering the barrier for weaponization (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify applications using saloonphp/saloon versions prior to 4.0.0 with OAuth2 functionality enabled, particularly those that cache AccessTokenAuthenticator state to disk or a shared cache store (e.g., Redis, Memcached, filesystem).
  2. Identify token storage location: Determine where the application stores serialized OAuth tokens — common locations include filesystem cache directories (e.g., /tmp, Laravel's storage/framework/cache) or shared cache backends.
  3. Craft a malicious serialized payload: Using a PHP gadget chain tool (e.g., PHPGGC), generate a serialized payload targeting a gadget chain available in the application's dependency set (e.g., Monolog's Logger chain) that executes arbitrary OS commands.
  4. Inject the payload: Overwrite or inject the malicious serialized string into the token cache location — this may be achieved via a file write vulnerability, misconfigured cache permissions, or a separate injection vector in the application.
  5. Trigger deserialization: Cause the application to load and deserialize the cached token by triggering an OAuth-authenticated request or a token refresh operation, which calls AccessTokenAuthenticator::unserialize() on the attacker-controlled data.
  6. Achieve RCE: PHP's unserialize() instantiates the gadget object and invokes its magic methods, executing the attacker's payload (e.g., a reverse shell or command execution) as the web server process (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected modification timestamps on cached token files in application cache directories (e.g., storage/framework/cache/, /tmp/); presence of serialized PHP strings beginning with O: or C: in cache files that do not correspond to AccessTokenAuthenticator objects.
  • Process: Unusual child processes spawned by the PHP-FPM or web server process (e.g., bash, sh, curl, wget, python, nc) that are not part of normal application behavior; unexpected outbound network connections from the web server process.
  • Logs: PHP error logs containing unserialize() warnings or errors referencing unexpected class names; application logs showing OAuth token refresh failures followed by unusual process activity.
  • Network: Unexpected outbound connections from the web server to external IPs on non-standard ports (indicative of reverse shell activity); DNS lookups for attacker-controlled domains originating from the web server process.

Mitigation and workarounds

The vulnerability is fully remediated in Saloon version 4.0.0, which removes PHP serialization entirely from the AccessTokenAuthenticator class. Users must upgrade to v4.0.0 or later and follow the migration guide to manually implement token storage and resolution. As an interim workaround prior to patching, restrict filesystem and cache backend permissions so that only the application process can read/write token cache files, and implement strict access controls to prevent unauthorized modification of serialized token storage. Review the official upgrade guide at https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4 for migration steps (GitHub Advisory, Github Advisory).

Community reactions

The vulnerability was published by maintainer @Sammyjo20 via GitHub Security Advisories on March 25, 2026, crediting @HuajiHD for discovery and @JonPurvis for the fix. The advisory was picked up by automated vulnerability tracking services including Red Hat CVE database, ENISA EUVD, and INCIBE-CERT shortly after disclosure. Social media mentions appeared on Mastodon and Bluesky via security-focused accounts, and the advisory was covered by The Hacker Wire (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management