
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33942 is an insecure deserialization vulnerability in the Saloon PHP library's AccessTokenAuthenticator class that can lead to object injection and remote code execution (RCE). It affects all versions of saloonphp/saloon prior to 4.0.0 and was disclosed on March 25–26, 2026. The vulnerability was discovered by researcher @HuajiHD and fixed by @JonPurvis. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 8.1 (High) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data). The vulnerable code in AccessTokenAuthenticator::unserialize() called PHP's native unserialize() with allowed_classes => true to restore OAuth token state from cache or storage, without restricting which classes could be instantiated. An attacker who can control the serialized string — for example, by overwriting a cached token file on disk or injecting data via another vulnerability — can supply a crafted serialized "gadget" object. When unserialize() processes this input, PHP instantiates the attacker-controlled object and automatically invokes its magic methods (__wakeup, __destruct, etc.), enabling object injection. In environments with common PHP dependencies such as Monolog, these gadget chains can be leveraged to achieve full RCE (GitHub Advisory, Github Advisory).
Successful exploitation can result in complete compromise of the affected system, with high impact to confidentiality, integrity, and availability. An attacker achieving RCE via a gadget chain can execute arbitrary commands as the web server process, exfiltrate sensitive data (including OAuth tokens and API credentials managed by Saloon), modify application data, or use the compromised host as a pivot point for lateral movement within the network. The attack requires no authentication and no user interaction, making it particularly dangerous for internet-facing applications that use Saloon's OAuth2 utilities (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.23% (46th percentile), indicating a relatively low near-term exploitation probability. The CVSSv4 exploit maturity is rated "Unreported." The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack vector is network-accessible with no privileges or user interaction required, and PHP deserialization gadget chains (e.g., via Monolog) are well-documented in the security community, lowering the barrier for weaponization (Github Advisory).
saloonphp/saloon versions prior to 4.0.0 with OAuth2 functionality enabled, particularly those that cache AccessTokenAuthenticator state to disk or a shared cache store (e.g., Redis, Memcached, filesystem)./tmp, Laravel's storage/framework/cache) or shared cache backends.Logger chain) that executes arbitrary OS commands.AccessTokenAuthenticator::unserialize() on the attacker-controlled data.unserialize() instantiates the gadget object and invokes its magic methods, executing the attacker's payload (e.g., a reverse shell or command execution) as the web server process (GitHub Advisory).storage/framework/cache/, /tmp/); presence of serialized PHP strings beginning with O: or C: in cache files that do not correspond to AccessTokenAuthenticator objects.bash, sh, curl, wget, python, nc) that are not part of normal application behavior; unexpected outbound network connections from the web server process.unserialize() warnings or errors referencing unexpected class names; application logs showing OAuth token refresh failures followed by unusual process activity.The vulnerability is fully remediated in Saloon version 4.0.0, which removes PHP serialization entirely from the AccessTokenAuthenticator class. Users must upgrade to v4.0.0 or later and follow the migration guide to manually implement token storage and resolution. As an interim workaround prior to patching, restrict filesystem and cache backend permissions so that only the application process can read/write token cache files, and implement strict access controls to prevent unauthorized modification of serialized token storage. Review the official upgrade guide at https://docs.saloon.dev/upgrade/upgrading-from-v3-to-v4 for migration steps (GitHub Advisory, Github Advisory).
The vulnerability was published by maintainer @Sammyjo20 via GitHub Security Advisories on March 25, 2026, crediting @HuajiHD for discovery and @JonPurvis for the fix. The advisory was picked up by automated vulnerability tracking services including Red Hat CVE database, ENISA EUVD, and INCIBE-CERT shortly after disclosure. Social media mentions appeared on Mastodon and Bluesky via security-focused accounts, and the advisory was covered by The Hacker Wire (GitHub Advisory, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."