CVE-2026-93467 PUBLISHED

HGiga|OAKlouds - Insecure Deserialization

Assigner: twcert
Reserved: 18.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor HGiga
Product OAKlouds-custom_page-2.0
Versions Default: unaffected
  • affected from 0 to 26 (excl.)
Vendor HGiga
Product OAKlouds-custom_page-3.0
Versions Default: unaffected
  • affected from 0 to 26 (excl.)
Vendor HGiga
Product OAKlouds-custom_page-4.0
Versions Default: unaffected
  • affected from 0 to 26 (excl.)

Solutions

Update OAKlouds-custom_page-2.0 version 26 or later Update OAKlouds-custom_page-3.0 version 26 or later Update OAKlouds-custom_page-4.0 version 26 or later

References

Problem Types

  • CWE-502 Deserialization of Untrusted Data CWE