Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
History

Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Mirasvit
Mirasvit full Page Cache Warmer For Magento 2
Vendors & Products Mirasvit
Mirasvit full Page Cache Warmer For Magento 2

Tue, 26 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
Title Mirasvit Cache Warmer for Magento < 1.11.12 PHP Object Injection
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-26T14:15:33.596Z

Updated: 2026-05-26T15:23:03.586Z

Reserved: 2026-05-11T14:14:49.613Z

Link: CVE-2026-45247

cve-icon Vulnrichment

Updated: 2026-05-26T15:22:59.350Z

cve-icon NVD

Status : Deferred

Published: 2026-05-26T15:16:39.263

Modified: 2026-05-26T19:50:21.747

Link: CVE-2026-45247

cve-icon Redhat

No data.