CVE-2026-18642: Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-otp-lock
Published Aug 3, 2026
·Updated
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection.
This issue affects eta-otp-lock: before 1.0.4.
Affected Software
1 affected component
TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock<1.0.4
Event History
Aug 3, 2026
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18642?
The severity of CVE-2026-18642 is rated high with a score of 7.8.
2
What type of vulnerability is CVE-2026-18642?
CVE-2026-18642 is a Remote Code Execution vulnerability caused by insecure deserialization.
3
Which versions of eta-otp-lock are affected by CVE-2026-18642?
CVE-2026-18642 affects eta-otp-lock versions before 1.0.4.
4
How do I fix CVE-2026-18642?
To fix CVE-2026-18642, upgrade eta-otp-lock to version 1.0.4 or later.
5
What consequences can arise from exploiting CVE-2026-18642?
Exploiting CVE-2026-18642 can lead to remote code execution, allowing attackers to execute arbitrary code on the affected system.