CVE-2026-78257
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 27, 2026 · Last modified: Aug 27, 2026 · CWE-502
Not enough EPSS history yet.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-100368.8 HIG—
———SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file within the configured checkpoint path to trigger code execution during candidate discovery, even if the malicious checkpoint is never selected for recovery.5hCVE-2026-782929.8 CRI—
———Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.8hCVE-2026-782869.8 CRI—
———Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.15hCVE-2026-782767.2 HIG—
———Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.8hCVE-2026-592756.6 MED—
———A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located in that process.
Spring AMQP 4.1.0
Spring AMQP 4.0.0 - 4.0.4
Spring AMQP 3.2.0 - 3.2.12
Spring AMQP 2.4.18 and earlier8hCVE-2026-478785.6 MED—
———DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist.
Spring Batch 6.0.0 - 6.0.4
Spring Batch 5.2.6 and earlier8h