Cyber Security News

Imunify AI-Bolit Vulnerability Let Execute Arbitrary Code and Escalate Privileges to Root

A serious security flaw was discovered in the AI-Bolit component of Imunify products. This vulnerability allows attackers to run arbitrary code and even become root on a server.

Imunify released a fix on October 23, 2025, and most servers have already received the automatic update. Currently, there are no reports of hackers exploiting this security flaw.

The flaw was found in the AI-Bolit scanner’s deobfuscation. Attackers could create a special file or database entry.

When AI-Bolit scans this, it could make the scanner run malicious PHP functions, leading to arbitrary code execution as the root user. The issue happened because the scanner used unfiltered input from files and databases.

Imunify AI-Bolit Vulnerability

This unsafe logic allowed hackers to abuse the scanning process if they managed to upload a crafted payload onto a protected server.

The danger came from two PHP functions within AI-Bolit’s code: deobfuscateDeltaOrd and deobfuscateEvalHexFunc.

They passed possibly unsafe strings to Helpers::executeWrapper(), which called those strings directly as PHP functions. Malicious input could run arbitrary code, escalating a hacker’s privileges to root.

The new patch adds strict controls so only safe functions can be called by the deobfuscator. Imunify confirms that there are no signs of this flaw being exploited in real-world attacks.

Imunify security process involves quietly fixing issues first, deploying fixes to users, and publishing advisories like this when it is safe to do so. If you use Imunify products, update the AI-Bolit component as soon as possible.

This will protect you against potential attacks that could allow hackers to run code or become root via crafted files or databases. Always keep automatic updates turned on for maximum safety.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago