Sploitus

Exploit for CVE-2026-77138

cve Β· 2026-08-25

Exploit Code

MARKDOWN2 lines
## https://sploitus.com/exploit?id=CVE-2026-77138
The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server.