LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40044

CVE-2026-40044 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 13, 2026

Pachno - Remote Code Execution

Published: April 13, 2026Updated: April 13, 2026Remote Exploitable

Overview

Pachno 1.0.6 contains an insecure deserialization vulnerability caused by unserializing attacker-controlled serialized objects in world-writable cache files during framework bootstrap, letting unauthenticated attackers execute arbitrary code.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can execute arbitrary code remotely, potentially leading to full system compromise.

Mitigation

Update to the latest version that fixes this vulnerability.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 13, 2026

šŸ”“ CVE-2026-40044 - Critical (9.8) Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40044/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 13, 2026

šŸ”“ CVE-2026-40044 - Critical (9.8) Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting malicious serialized objects into cache files. Attackers can write PHP object payloads to world-writable cache files... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40044/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-40044
Severity
Critical
CVSS Score
9.8
Type
insecure_deserialization
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-502

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days