Junglewise Threat Intelligence

CVE-2026-93467: HGiga OAKlouds insecure deserialization in custom_page

CVE-2026-93467 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Executive brief

HGiga OAKlouds is a cloud-based content management platform used to manage custom pages and bulletins on web applications. The custom_page module contains an insecure deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code on the server by sending maliciously crafted serialized data, potentially compromising the entire system and any data it stores.

Technical details

The vulnerability is an insecure deserialization flaw in the OAKlouds custom_page module (versions 2.0, 3.0, and 4.0 before version 26). Unauthenticated remote attackers can exploit this by sending specially crafted serialized objects to the affected application, which deserializes the content without proper validation. Since no authentication is required and the attack vector is network-based, an attacker can directly trigger remote code execution on the server. The vulnerability affects custom_page-2.0, custom_page-3.0, and custom_page-4.0 versions before 26, and patches are available by updating to version 26 or later.

Affected products

  • HGiga OAKlouds custom_page 2.0, 3.0, 4.0 before version 26

Timeline

  • 2026-09-18: disclosed

References