---
title: "CVE-2026-7261\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-7261?format=md
keywords: index, follow
---

# CVE-2026-7261

Publication date 10 May 2026

Last updated 6 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.8 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2026-7261?format=md#impact-score)

Toggle side navigation

## Description

In PHP versions 8.2.\* before 8.2.31, 8.3.\* before 8.3.31, 8.4.\* before
8.4.21, and 8.5.\* before 8.5.6, when SoapServer is configured with
SOAP\_PERSISTENCE\_SESSION, the handler object is persisted across requests
via session storage. However, in the case SOAP requests results in an
error, the persistance is handled incorrectly, resulting in freeing the
object while keeping a pointer to it, which may lead to use-after-free.
This may lead to memory corruption, information disclosure, or process
crashes, with confidentiality, integrity, and availability impact on the
vulnerable system.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-7261?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php7.0 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 16.04 LTS xenial | Fixed 7.0.33-0ubuntu0.16.04.16+esm19  Ubuntu Pro |
| php5 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Needs evaluation |
| php7.2 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 18.04 LTS bionic | Needs evaluation |
| php7.4 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Needs evaluation |
| php8.1 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Fixed 8.1.2-1ubuntu2.24 |
| php8.3 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Fixed 8.3.6-0ubuntu0.24.04.9 |
| 22.04 LTS jammy | Not in release |
| php8.4 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Fixed 8.4.11-1ubuntu1.2 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| php8.5 | 26.04 LTS resolute | Fixed 8.5.4-0ubuntu1.1 |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2026-7261?format=md#patch-details)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

PEAR issues should go against php-pear as of xenial

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| php8.5 | * Upstream:   [db2a7f9](https://github.com/php/php-src/commit/db2a7f9348fd5dda5fd162061786a664c417bf5b) |

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2026-7261?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2026-7261?format=md)

**Base score**

6.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | Present |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | Low |
  | Vulnerable system - Integrity impact | Low |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | Low |
  | Subsequent system - Integrity impact | Low |
  | Subsequent system - Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.3 · Medium |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:P/AU:Y/RE:M/U:Amber

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-7261)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-7261)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-7261)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-7261)

### Related Ubuntu Security Notices (USN)

+ [USN-8336-1](https://usn.ubuntu.com/USN-8336-1)
+ PHP vulnerabilities
+ 28 May 2026

+ [USN-8513-1](https://usn.ubuntu.com/USN-8513-1)
+ PHP vulnerabilities
+ 6 July 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-7261>
* <https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q>
