CVE-2026-56032: Buddyboss Platform

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

Affected products

  • Buddyboss Buddyboss Platform: up to and including 3.0.4

Published 2026-06-26. Last modified 2026-06-26.