Exploit for CVE-2026-82226

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 via create_order maybe_unserialize.

Published 18 Sep 2026Updated 18 Sep 20263 sources
CVSS 9.8 ✓ VERIFIED REFERENCE

Source timeline

Discovered through SploitusView source ↗