CVE-2026-49400 | OctoberCMS October up to 3.7.16/4.2.22 SessionMaker unserialize deserialization
A vulnerability was found in OctoberCMS October up to 3.7.16/4.2.22 and classified as problematic. Affected by this issue is the function unserialize of the component SessionMaker. Executing a manipulation can lead to deserialization.
The identification of this vulnerability is CVE-2026-49400. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More