Junglewise Threat Intelligence

CVE-2026-78032: SOY CMS unsafe deserialization

CVE-2026-78032 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Executive brief

SOY CMS is a web content management system used to build and maintain websites. This vulnerability allows an attacker with web server privileges to execute arbitrary code on the server, potentially compromising the entire website and any data it stores. An attacker could modify content, steal sensitive information, or use the compromised server to attack other systems.

Technical details

SOY CMS versions 3.24.0 and earlier contain a deserialization of untrusted data vulnerability (CWE-502). The vulnerability allows an attacker to execute arbitrary code with the privileges of the web server process. The vulnerability is triggered during PHP deserialization of untrusted input; exploitation requires network access and is not gated by authentication or user interaction. This affects PHP 7.0 and later environments. The vendor released patched versions (SOY CMS 3.25.0 and later) on 2026-08-31.

Affected products

  • Tsuyoshi Saito SOY CMS 3.24.0 and earlier

Timeline

  • 2026-08-28: disclosed
  • 2026-08-31: patched: SOY CMS 3.25.0 released

References