CVE-2026-45247: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
Other sources
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mirasvit Cache Warmer for Magentoto a version that resolves this vulnerability.Fixed in 1.11.12 - Upgrade
Upgrade
Mirasvit Full Page Cache Warmerto a version that resolves this vulnerability.Fixed in 1.11.12
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45247?
CVE-2026-45247 has a critical severity score of 9.8, indicating a significant risk to systems.
How do I fix CVE-2026-45247?
To fix CVE-2026-45247, upgrade the Mirasvit Full Page Cache Warmer for Magento to version 1.11.12 or later.
What type of vulnerability is CVE-2026-45247?
CVE-2026-45247 is a PHP object injection vulnerability that can lead to remote code execution.
Who is affected by CVE-2026-45247?
Any user running versions of Mirasvit Full Page Cache Warmer for Magento 2 prior to 1.11.12 is affected by CVE-2026-45247.
How can attackers exploit CVE-2026-45247?
Attackers can exploit CVE-2026-45247 by sending a crafted serialized PHP object through the CacheWarmer cookie.