CVE-2026-56032: Buddyboss Platform
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
Affected products
- Buddyboss Buddyboss Platform: up to and including 3.0.4
Published 2026-06-26. Last modified 2026-06-26.