Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-82226 — Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction and patch guidance. | Kitploit
도구/GitHubGitHub/abraxas/cve-2026-82226
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-82226

CVE-2026-82226

Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction and patch guidance.

저장소 보기
272일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Abraxas Labs - CVE-2026-82226

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-82226

CVE-2026-82226

Tickera 3.6.0.2 - Tickera

I am @abraxas_null. Loopback lab. The client is CVE-2026-82226-Abraxas-Labs.py.

Checkout unserializes the attendee. Unauthenticated cart -> process-payment. create_order maybe_unserializes owner _post_meta. Objects instantiate. Patched in 3.6.0.3. Not admin-ajax action=create_order.

CVECVE-2026-82226 · CVE.org
CWECWE-502
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductTickera
Affectedall versions through 3.6.0.2 (inclusive)
Patched3.6.0.3 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Fill a free-order checkout with a serialized object in owner_data_first_name_post_meta. create_order builds that class during payment. A POP gadget on a real autoload is RCE. The lab ships a canary class, not a gadget.


How I found it

Patchstack named object injection. I read update_cart, then create_order around the _post_meta branch.

Discover like a visitor: ticket id, COOKIEHASH, cart path, payment path, cart nonce (tickera_cart_page). POST cart_action=proceed_to_checkout with the canary in _post_meta, not in the email. Then POST process-payment with tc_payment_submit and free_orders. Follow Location. Checkout 302s. Process-payment 302s. The canary may echo into HTML before the redirect script.

Wrong turns: admin-ajax.php action=create_order (theme); Invalid cart request (wrong nonce); The cart is empty (missing tc_cart_{COOKIEHASH} or wrong ticket id); All fields marked with * are required (empty name/email); stopping at the payment 302.


The lab

Port 8088. Tickera 3.6.0.2. Public fixture page with ticket id and paths. Free orders on.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-82226-Abraxas-Labs.py

Witness: POCWitness82226 in the confirmation body or debug.log. Theme HTML, invalid cart nonce, or empty cart is not it.

Ways to lose without learning anything:

  • generic 200 hello-world HTML
  • Invalid cart request / empty cart / required fields
  • status success without unserialize / class instantiation
  • reverse shell

The fix

Update Tickera to 3.6.0.3 or newer. Re-run CVE-2026-82226-Abraxas-Labs.py against the patched build: POCWitness82226 must not appear.


References

  • CVE-2026-82226 · NVD

  • CVE-2026-82226 · CVE.org

  • patchstack.com/database/wordpress/plugin/tickera-event-ticketing-system/vulnerability/wordpress-tickera-plugin-3-6-0-2-php-object-injection-vulnerability?_s_id=cve

  • github.com/advisories/GHSA-v3jw-vq2p-6xp9

  • nvd.nist.gov/vuln/detail/CVE-2026-82226

  • Plugin directory: tickera-event-ticketing-system

  • Trac browser: plugins.trac.wordpress.org/tickera-event-ticketing-system

  • SVN tags: plugins.svn.wordpress.org/tickera-event-ticketing-system

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

도구 다운로드