Description
Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files with predictable names in the cache directory, which are unserialized during framework bootstrap before authentication checks occur.
Problem types
Deserialization of Untrusted Data
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5986.php (Zero Science Lab Disclosure)
www.vulncheck.com/...e-deserialization-remote-code-execution (VulnCheck Advisory: Pachno 1.0.6 FileCache Deserialization Remote Code Execution)