What is CVE-2026-57859?
CVE-2026-57859 is a code execution vulnerability in the `e_array` deserialization handler of e107 prior to version 2.3.8. It allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the `user_prefs` column. Users should immediately upgrade to version 2.3.8 or later.
Azərbaycanca: CVE-2026-57859, e107 platformunun 2.3.8-dən əvvəlki versiyalarında `e_array` deserialization idarəedicisində kod icrası zəifliyidir. Bu zəiflik aut-of-band verilənlər bazası yazma icazəsi olan hücumçuya `user_prefs` sütununda xüsusi hazırlanmış yük saxlamaqla ixtiyari PHP kodu icra etməyə imkan verir. İstifadəçilər dərhal 2.3.8 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
What level of access does an attacker need to exploit CVE-2026-57859?
The attacker needs out-of-band database write access.
Which version of the e107 platform is recommended to remediate CVE-2026-57859?
Users should upgrade to version 2.3.8 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.