PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97865 Open-Web-Analytics CVE debrief

A security flaw has been discovered in Open-Web-Analytics up to 1.8.1, affecting the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint, allowing for deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 addresses this issue with patch 78c1222ec0e2119d84684032da1541120a2cdd23. This vulnerability has a medium severity and defenders should assess exposure and prioritize upgrading to version 1.8.2. The affected component should be reviewed for potential security risks and verify patch application to prevent deserialization attacks.

Vendor
Open-Web-Analytics
Product
Open-Web-Analytics
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Open-Web-Analytics installations up to version 1.8.1 should assess exposure and prioritize upgrading to version 1.8.2. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review the affected component for potential security risks and verify patch application to prevent deserialization attacks. Defenders should also assess exposure of Remote Event Queue Endpoint and plan

Why it matters

CVE-2026-97865 is a medium-severity vulnerability in Open-Web-Analytics up to 1.8.1, allowing for deserialization attacks. Defenders should prioritize upgrading to version 1.8.2 and review the affected component for potential exposure.

  • Verify patch application to prevent deserialization attacks
  • Assess exposure of Remote Event Queue Endpoint
  • Prioritize upgrade to version 1.8.2
  • Review component for potential security risks

Technical summary

The function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint in Open-Web-Analytics up to 1.8.1 is vulnerable to deserialization. This allows for a remote attack, which can be addressed by upgrading to version 1.8.2. The vulnerability has a CVSS score of 6.9 and is considered medium-severity. Defenders should prioritize upgrading to version 1.8.2 and review the affected component for potential exposure to prevent deserialization attacks. The patch 78c1222ec0e2119d84684032da1541120a2cdd23 should be verified.

Defensive priority

Defenders should prioritize upgrading to version 1.8.2 and review the affected component for potential exposure.

Recommended defensive actions

  • Upgrade to version 1.8.2
  • Review the affected component for potential exposure
  • Verify the patch 78c1222ec0e2119d84684032da1541120a2cdd23 is applied
  • Assess exposure of Remote Event Queue Endpoint
  • Verify patch application to prevent deserialization attacks
  • Prioritize upgrade to version 1.8.2
  • Review component for potential security risks

Evidence notes

The CVE record and source metadata indicate a medium-severity vulnerability in Open-Web-Analytics up to 1.8.1, with a CVSS score of 6.9. The affected component and potential attack vectors require verification. Defenders should verify the patch 78c1222ec0e2119d84684032da1541120a2cdd23 is applied and review the affected component for potential exposure. Evidence limits and source grounding suggest that defenders should prioritize upgrading to version 1.8.2 and assess exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97865 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97865

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97865 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97865

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.