Vulnerability Description
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mirasvit | Full Page Cache Warmer | < 1.11.12 |
Related Weaknesses (CWE)
References
- https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmerRelease Notes
- https://sansec.io/research/mirasvit-cache-warmer-object-injectionThird Party Advisory
- https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-objecThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-US Government Resource
- https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-Third Party Advisory
FAQ
What is CVE-2026-45247?
CVE-2026-45247 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a...
How severe is CVE-2026-45247?
CVE-2026-45247 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-45247?
Check the references section above for vendor advisories and patch information. Affected products include: Mirasvit Full Page Cache Warmer.