CVE-2026-97257: Deserialization of Untrusted Data in PressTigers Simple Event Planner
Description
CVE-2026-97257 is a high-severity vulnerability in PressTigers Simple Event Planner up to version 1.5.7. It involves deserialization of untrusted data, allowing object injection. This can lead to complete compromise of confidentiality, integrity, and availability. The vulnerability affects versions from initial releases through 1.5.7.
CVSS v3.1
Score 8.8high
Affected software
PressTigers
Simple Event Planner
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in PressTigers Simple Event Planner (versions prior to 1.5.8) allows an attacker to perform deserialization of untrusted data, resulting in object injection. This flaw can be exploited remotely with low complexity and no user interaction, requiring only low privileges. The impact includes full compromise of confidentiality, integrity, and availability of the affected system, as indicated by a CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Potential Impact
Successful exploitation can lead to complete system compromise, including unauthorized access to sensitive data, modification or destruction of data, and denial of service. The vulnerability is remotely exploitable with low attack complexity and no user interaction, though it requires low privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid processing untrusted serialized data and restrict access to the affected application to trusted users only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Patchstack
- Date Reserved
- 2026-09-24T10:23:10.131Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac3f8302cdf04f6563003ec
Added to database: 10/05/2026, 19:19:12 UTC
Last enriched: 10/05/2026, 19:33:10 UTC
Last updated: 10/05/2026, 19:34:03 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.