What is CVE-2026-18634?
An insecure handling of serialized objects vulnerability was found in a service of the GMS application version 9.5.1 (Build 9510.1044) and earlier. This flaw could allow a local attacker with the ability to interact with the service to perform unauthorized actions through the affected component.
Azərbaycanca: GMS tətbiqinin 9.5.1 (Build 9510.1044) və əvvəlki versiyalarındakı bir xidmətdə seriallaşdırılmış obyektlərin təhlükəli işlənməsi zəifliyi aşkar edilib. Bu zəiflik, xidmətlə qarşılıqlı əlaqə qura bilən lokal təcavüzkara təsirə məruz qalan servis vasitəsilə icazəsiz əməliyyatlar icra etməyə imkan verə bilər.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
What privileges does an attacker need to exploit the CVE-2026-18634 vulnerability?
To exploit this vulnerability, an attacker must have local access to the system and be able to interact with the relevant service of the GMS application.
Which versions of the GMS application are affected by CVE-2026-18634?
GMS application version 9.5.1 (Build 9510.1044) and all earlier versions are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.