CVE-2026-78032: Critical severity vulnerability
Published Aug 28, 2026
·Updated
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
Event History
Aug 28, 2026
CVE Published
via MITRE·06:11 AM
Data Sourced
via MITRE·06:11 AM
DescriptionSeverity
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
2
What privileges would code run with after successful exploitation?
Arbitrary code may execute with the privileges of the web server.