CVE-2026-93467: HGiga|OAKlouds - Insecure Deserialization
The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OAKlouds-custom_page-2.0to a version that resolves this vulnerability.Fixed in 26 - Upgrade
Upgrade
OAKlouds-custom_page-3.0to a version that resolves this vulnerability.Fixed in 26 - Upgrade
Upgrade
OAKlouds-custom_page-4.0to a version that resolves this vulnerability.Fixed in 26
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An unauthenticated remote attacker can exploit it. No prior account or user interaction is required.
What must an attacker send to trigger the issue?
The attacker needs to send maliciously crafted serialized content to the affected server. Successful exploitation can result in arbitrary code execution on that server.
What is the potential impact of successful exploitation?
Successful exploitation can allow arbitrary code execution with high impact to confidentiality, integrity, and availability.