CVE-2026-33942Disclosure(saloon / saloon)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unserialize() to restore OAuth token state from cache or storage, with allowed_classes => true. An attacker who can control the serialized string (e.g. by overwriting a cached token file or via another injection) can supply a serialized "gadget" object. When unserialize() runs, PHP instantiates that object and runs its magic methods (__wakeup, __destruct, etc.), leading to object injection. In environments with common dependencies (e.g. Monolog), this can be chained to remote code execution (RCE). The fix in version 4.0.0 removes PHP serialization from the AccessTokenAuthenticator class requiring users to store and resolve the authenticator manually.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • saloon

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
saloon

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-26: 3Technical Details · 2026-03-26: 203-26
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Fernando Karl@fernandokarl
    General

    🔒 Stay informed! CVE-2026-33942 has been identified, posing critical security risks. Ensure your systems are patched and secure. 💻 How are you managing vulnerabilities in your environment? Let’s discuss! #CyberSecurity #ThreatIntel https://www.tenable.com/cve/CVE-2026-33942

    Post summary

    The post merely announces the existence of CVE-2026-33942 and urges general remediation without providing specific technical or exploit details.

    0000051
    258 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33942 Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's unserialize() in AccessTokenAuthenticator::unser… https://www.cve.org/CVERecord?id=CVE-2026-33942

    Post summary

    The statement announces CVE‑2026‑33942, noting that older versions of the Saloon PHP library use PHP's unserialize(), highlighting a likely RCE vulnerability, but it does not provide a PoC, exploit, or patch details.

    00000122
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33942 - Saloon has insecure deserialization in AccessTokenAuthenticator (object injection / RCE) Intel Report: https://ift.tt/qVgoLZz

    Post summary

    The tweet reports a new CVE (CVE-2026-33942) affecting Saloon's AccessTokenAuthenticator, highlighting insecure deserialization that enables RCE, and links to an Intel report.

    0000032
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsaloonsaloon---

Explore more