
Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction and patch guidance.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-82226
Tickera 3.6.0.2 - Tickera
I am @abraxas_null. Loopback lab. The client is CVE-2026-82226-Abraxas-Labs.py.
Checkout unserializes the attendee. Unauthenticated cart -> process-payment. create_order maybe_unserializes owner _post_meta. Objects instantiate. Patched in 3.6.0.3. Not admin-ajax action=create_order.
| CVE | CVE-2026-82226 · CVE.org |
| CWE | CWE-502 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | Tickera |
| Affected | all versions through 3.6.0.2 (inclusive) |
| Patched | 3.6.0.3 and later |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Fill a free-order checkout with a serialized object in owner_data_first_name_post_meta. create_order builds that class during payment. A POP gadget on a real autoload is RCE. The lab ships a canary class, not a gadget.
Patchstack named object injection. I read update_cart, then create_order around the _post_meta branch.
Discover like a visitor: ticket id, COOKIEHASH, cart path, payment path, cart nonce (tickera_cart_page). POST cart_action=proceed_to_checkout with the canary in _post_meta, not in the email. Then POST process-payment with tc_payment_submit and free_orders. Follow Location. Checkout 302s. Process-payment 302s. The canary may echo into HTML before the redirect script.
Wrong turns: admin-ajax.php action=create_order (theme); Invalid cart request (wrong nonce); The cart is empty (missing tc_cart_{COOKIEHASH} or wrong ticket id); All fields marked with * are required (empty name/email); stopping at the payment 302.
Port 8088. Tickera 3.6.0.2. Public fixture page with ticket id and paths. Free orders on.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-82226-Abraxas-Labs.py
Witness: POCWitness82226 in the confirmation body or debug.log. Theme HTML, invalid cart nonce, or empty cart is not it.
Ways to lose without learning anything:
Update Tickera to 3.6.0.3 or newer. Re-run CVE-2026-82226-Abraxas-Labs.py against the patched build: POCWitness82226 must not appear.
Plugin directory: tickera-event-ticketing-system
Trac browser: plugins.trac.wordpress.org/tickera-event-ticketing-system
SVN tags: plugins.svn.wordpress.org/tickera-event-ticketing-system
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.