CVE-2026-45247
published 2026-05-26CVE-2026-45247: Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to…
critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
KEV
CISA Known Exploited Vulnerabilitydue 2026-06-06
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mirasvit | full_page_cache_warmer | < 1.11.12 | 1.11.12 |
| mirasvit | full_page_cache_warmer_for_magento_2 | < 1.11.12 | 1.11.12 |
CVSS provenance
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.3CRITICAL
cisa9.3CRITICAL
VulDB
Mirasvit Full Page Cache Warmer for Magento 2 up to 1.11.11 on Magento unserialize deserialization (EUVD-2026-31837)
vuldb·2026-06-03·CVSS 9.3
CVE-2026-45247 [CRITICAL] Mirasvit Full Page Cache Warmer for Magento 2 up to 1.11.11 on Magento unserialize deserialization (EUVD-2026-31837)
A vulnerability described as critical has been identified in Mirasvit Full Page Cache Warmer for Magento 2 up to 1.11.11 on Magento. Affected is the function unserialize. Executing a manipulation can lead to deserialization.
This vulnerability is registered as CVE-2026-45247. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
GHSA
GHSA-rg8p-9rpg-r32p: Mirasvit Full Page Cache Warmer for Magento 2 before version 1
ghsa_unreviewed·2026-05-26
CVE-2026-45247 [CRITICAL] CWE-502 GHSA-rg8p-9rpg-r32p: Mirasvit Full Page Cache Warmer for Magento 2 before version 1
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
VulnCheck
Deserialization of Untrusted Data
vulncheck·2026·CVSS 9.3
CVE-2026-45247 [CRITICAL] Deserialization of Untrusted Data
Deserialization of Untrusted Data
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/
CISA
Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
cisa·2026-06-03·CVSS 9.3
CVE-2026-45247 [CRITICAL] CWE-502 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Vulnerability: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Affected: Mirasvit Mirasvit Full Page Cache Warmer
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer ; https://nvd.nist.gov/vuln/detail/CVE-2026-45247
Remediation Due Date: 2026-06-06
No detection rules found.
No public exploits indexed.
https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmerhttps://sansec.io/research/mirasvit-cache-warmer-object-injectionhttps://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injectionhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45247https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/
2026-05-26
Published
2026-06-03
Added to CISA KEV