Skip to main content
Vulnerability Database/CVE-2026-61686

CVE-2026-61686: SolidInvoice PHP Deserialization RCE Flaw

CVE-2026-61686 is a PHP deserialization flaw in SolidInvoice that enables authenticated attackers to execute arbitrary code through malicious serialized payloads. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-61686 Overview

CVE-2026-61686 is an insecure deserialization vulnerability in SolidInvoice, an open-source invoicing platform. The DataGrid LiveComponent deserializes a context prop value using PHP's unserialize() function after receiving it directly from the client. Because the prop is marked writable: true, an authenticated attacker can supply an arbitrary PHP serialized payload. This behavior maps to [CWE-502: Deserialization of Untrusted Data]. The maintainers addressed the issue in SolidInvoice version 3.0.1.

Critical Impact

An authenticated attacker can submit a crafted serialized payload to the DataGrid LiveComponent, triggering object instantiation that can compromise the confidentiality, integrity, and availability of the SolidInvoice instance.

Affected Products

  • SolidInvoice versions prior to 3.0.1
  • SolidInvoice DataGrid LiveComponent (context prop)
  • Deployments exposing authenticated SolidInvoice interfaces to untrusted users

Discovery Timeline

  • 2026-09-04 - CVE-2026-61686 published to the National Vulnerability Database
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-61686

Vulnerability Analysis

SolidInvoice uses the Symfony UX LiveComponent pattern, which round-trips component state between the browser and the server. The DataGrid LiveComponent exposes a context prop configured as writable: true, allowing the client to submit an updated value for that prop. On the server side, SolidInvoice passes the client-supplied string to PHP's unserialize() function to reconstruct the component context.

Because unserialize() instantiates arbitrary PHP objects and invokes magic methods such as __wakeup(), __destruct(), and __toString() during deserialization, an authenticated attacker can craft a serialized payload that chains reachable classes into a POP (Property-Oriented Programming) gadget. Available gadgets depend on the classes loaded by the SolidInvoice runtime and its Composer dependencies, but historically Symfony and Doctrine components have exposed sinks that lead to file writes, SQL execution, or command execution.

Root Cause

The root cause is trust in client-controlled data during object reconstruction. Marking the context prop as writable: true combined with the use of unserialize() on that value violates the principle that PHP deserialization must only be applied to trusted, integrity-protected input. Safer alternatives such as JSON decoding or signed payloads were not used.

Attack Vector

Exploitation requires an authenticated session on the target SolidInvoice instance. The attacker sends a LiveComponent update request to the endpoint backing the DataGrid component with a context value set to a PHP serialized string. When the server rehydrates the component, unserialize() triggers the gadget chain. Refer to the GitHub Security Advisory GHSA-4gj8-frx2-gmp6 for maintainer-provided technical details.

No verified proof-of-concept code has been published. The vulnerability mechanism is described in prose only.

Detection Methods for CVE-2026-61686

Indicators of Compromise

  • LiveComponent HTTP requests where the context prop contains PHP serialization markers such as O:, a:, or s: at the start of the value.
  • Unexpected PHP-FPM or web worker child processes spawning shells, invoking curl/wget, or writing to web-writable directories.
  • New or modified files under the SolidInvoice document root or cache directories that were not produced by an application deployment.
  • Outbound network connections from the SolidInvoice host to previously unseen IPs immediately following LiveComponent activity.

Detection Strategies

  • Inspect web server and application logs for POST requests to LiveComponent endpoints referencing the DataGrid component with abnormally long context values.
  • Add web application firewall (WAF) rules that flag serialized PHP object markers in request bodies for authenticated application endpoints.
  • Correlate authenticated user sessions with subsequent process, file, and network activity on the SolidInvoice host to surface deserialization-driven execution.

Monitoring Recommendations

  • Enable PHP error and exception logging to capture unexpected __wakeup() or __destruct() failures that indicate failed gadget attempts.
  • Forward web, PHP-FPM, and host telemetry to a centralized analytics platform and alert on child processes of the web server such as sh, bash, or php -r.
  • Track the SolidInvoice application version across environments and alert when hosts remain on releases prior to 3.0.1.

How to Mitigate CVE-2026-61686

Immediate Actions Required

  • Upgrade SolidInvoice to version 3.0.1 or later on all affected instances.
  • Rotate authenticated user credentials and API tokens if suspicious LiveComponent activity is present in logs.
  • Restrict network access to SolidInvoice administrative and authenticated interfaces to trusted networks or a VPN until patching completes.
  • Review the SolidInvoice host for unexpected files, cron jobs, and outbound connections.

Patch Information

SolidInvoice 3.0.1 remediates the issue by removing the unsafe unserialize() call on client-controlled input for the DataGrid LiveComponent context prop. Release notes and the fix are documented in the SolidInvoice 3.0.1 release and the GitHub Security Advisory GHSA-4gj8-frx2-gmp6.

Workarounds

  • If immediate upgrade is not possible, restrict access to authenticated SolidInvoice endpoints using network controls or reverse-proxy authentication.
  • Deploy a WAF rule that blocks request bodies containing PHP serialization signatures (O:<digits>:", a:<digits>:{) on LiveComponent routes.
  • Audit user accounts and disable or downgrade accounts that do not require access to invoicing functionality.
bash
# Example WAF pattern to block PHP serialized payloads on LiveComponent routes
# ModSecurity rule (illustrative)
SecRule REQUEST_URI "@contains /_components/" \
  "phase:2,deny,status:400,id:1006861,\
   msg:'Blocked PHP serialized payload to LiveComponent',\
   chain"
  SecRule REQUEST_BODY "@rx (?:^|&|=)(?:O|a|s):[0-9]+:"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.