Exploit for CVE-2026-82226

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 via create_order maybe_unserialize.

Published 18 Sep 2026Updated 18 Sep 20263 sources
CVSS 9.8 ✓ VERIFIED REFERENCE

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.