PatchSiren cyber security CVE debrief
CVE-2026-97865 Open-Web-Analytics CVE debrief
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1, affecting the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint, allowing for deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 addresses this issue with patch 78c1222ec0e2119d84684032da1541120a2cdd23. This vulnerability has a medium severity and defenders should assess exposure and prioritize upgrading to version 1.8.2. The affected component should be reviewed for potential security risks and verify patch application to prevent deserialization attacks.
- Vendor
- Open-Web-Analytics
- Product
- Open-Web-Analytics
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Open-Web-Analytics installations up to version 1.8.1 should assess exposure and prioritize upgrading to version 1.8.2. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review the affected component for potential security risks and verify patch application to prevent deserialization attacks. Defenders should also assess exposure of Remote Event Queue Endpoint and plan
Why it matters
CVE-2026-97865 is a medium-severity vulnerability in Open-Web-Analytics up to 1.8.1, allowing for deserialization attacks. Defenders should prioritize upgrading to version 1.8.2 and review the affected component for potential exposure.
- Verify patch application to prevent deserialization attacks
- Assess exposure of Remote Event Queue Endpoint
- Prioritize upgrade to version 1.8.2
- Review component for potential security risks
Technical summary
The function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint in Open-Web-Analytics up to 1.8.1 is vulnerable to deserialization. This allows for a remote attack, which can be addressed by upgrading to version 1.8.2. The vulnerability has a CVSS score of 6.9 and is considered medium-severity. Defenders should prioritize upgrading to version 1.8.2 and review the affected component for potential exposure to prevent deserialization attacks. The patch 78c1222ec0e2119d84684032da1541120a2cdd23 should be verified.
Defensive priority
Defenders should prioritize upgrading to version 1.8.2 and review the affected component for potential exposure.
Recommended defensive actions
- Upgrade to version 1.8.2
- Review the affected component for potential exposure
- Verify the patch 78c1222ec0e2119d84684032da1541120a2cdd23 is applied
- Assess exposure of Remote Event Queue Endpoint
- Verify patch application to prevent deserialization attacks
- Prioritize upgrade to version 1.8.2
- Review component for potential security risks
Evidence notes
The CVE record and source metadata indicate a medium-severity vulnerability in Open-Web-Analytics up to 1.8.1, with a CVSS score of 6.9. The affected component and potential attack vectors require verification. Defenders should verify the patch 78c1222ec0e2119d84684032da1541120a2cdd23 is applied and review the affected component for potential exposure. Evidence limits and source grounding suggest that defenders should prioritize upgrading to version 1.8.2 and assess exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97865 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97865
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97865 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97865
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Open-Web-Analytics/Open-Web-Analytics/
-
Source reference
Unverified legacy reference
URL: https://github.com/Open-Web-Analytics/Open-Web-Analytics/commit/78c1222ec0e2119d84684032da1541120a2cdd23
-
Source reference
Unverified legacy reference
URL: https://github.com/Open-Web-Analytics/Open-Web-Analytics/issues/960
-
Source reference
Unverified legacy reference
URL: https://github.com/Open-Web-Analytics/Open-Web-Analytics/pull/967
-
Source reference
Unverified legacy reference
URL: https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.8.2
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-97865
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/911108
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/409882
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.