External risk intelligence

b2evolution CMS Object Injection via Negative Integer Array Key

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-76834

The vulnerability affects a CMS, which is designed to be a public-facing web application. The vulnerable endpoint, htsrv/call_plugin.php, is a network-accessible component of the web application framework, making it reachable by external traffic in standard deployments where the CMS serves public content.

Deserialization

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical security flaw found in b2evolution CMS, a content management system. The vulnerability allows unauthenticated attackers to execute arbitrary code by submitting specially crafted data, potentially impacting any organization using the affected versions. The primary concern is to confirm if this technology is in use and assess any potential exposure.

  • Attackers can run any code on affected systems.
  • Critical flaw impacts a common web content platform.
  • Confirm relevance and investigate exposure risks.

Attack Path

How an attacker could exploit the issue

An attacker could target this vulnerability by sending specially crafted POST requests to the `htsrv/call_plugin.php` endpoint. This allows unauthenticated attackers to bypass security checks by submitting serialized PHP objects with negative integer array keys. If suitable chains of code exist, this could lead to the instantiation of arbitrary PHP objects, potentially enabling arbitrary code execution.

  • Attacker sends POST request to vulnerable endpoint.
  • Malicious serialized objects bypass validation.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect the integrity and availability of a b2evolution CMS. When supported by the advisory, an unauthenticated attacker could submit specially crafted POST requests to a plugin endpoint, bypassing validation and potentially executing arbitrary PHP code by instantiating chosen objects. This could occur when the affected CMS is configured to allow unauthenticated access to the `htsrv/call_plugin.php` endpoint.

  • System data and service behavior.
  • Crafted POST requests bypass validation.
  • Potential for arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

System owners responsible for b2evolution CMS deployments must first locate all instances of the affected software, verify its external reachability and business criticality, and identify the accountable application owner. Remediation planning should then be prioritized based on these findings.

  • Application owners should manage the issue.
  • Verify external reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is b2evolution CMS?

b2evolution is a content management system used to build and maintain websites, blogs, and community forums. It provides a framework for organizing digital content and managing user interactions, often serving as the foundation for public-facing web platforms.

What does CVE-2026-76834 mean by deserialization?

This vulnerability involves 'Insecure Deserialization' (CWE-502). The software improperly processes data structures, allowing an attacker to bypass security filters. By submitting specifically formatted data, the system is tricked into creating unauthorized internal objects, which can be misused to execute unintended commands on the server.

How do attackers trigger this vulnerability?

An attacker sends a crafted POST request to the htsrv/call_plugin.php file. The flaw is triggered when the input includes a serialized PHP object containing a negative integer array key, which the system fails to block. Simply visiting the site or performing standard GET requests does not trigger this specific issue.

Is my instance affected by this CVE?

According to Halo Surface Signal, this vulnerability is particularly relevant to b2evolution CMS because it is a web-based platform often exposed to the internet. Because the vulnerable endpoint is a standard component of the CMS, any installation reachable by public network traffic faces a higher risk of being targeted by external actors.

What should I do if I run b2evolution?

First, identify all servers running the affected versions to determine where the software is deployed. Check whether these instances are accessible from the internet and evaluate their business importance. Once you have an inventory of your deployments, prioritize them for remediation and consult the vendor for the appropriate updates or configuration changes.

References