Shiftup · Shiftup · CVE-2026-40733
**Name of the Vulnerable Software and Affected Versions**
ShiftUp versions 1.3 and earlier
**Description**
An unauthenticated PHP Object Injection issue exists in the software. PHP Object Injection occurs when user-supplied input is passed to the `unserialize()` function without proper validation, potentially allowing an attacker to manipulate the application logic or execute arbitrary code.
**Recommendations**
Disable or isolate the software immediately.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.