CVE-2026-45247 Details
Description
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
A PHP object injection vulnerability has been identified in Mirasvit Full Page Cache Warmer for Magento 2, in versions prior to 1.11.12. This vulnerability allows unauthenticated attackers to execute remote code by sending a crafted serialized PHP object in the CacheWarmer cookie. The issue arises from an unrestricted call to PHP's native unserialize() function, which can be exploited using gadget chains available in Magento and its dependencies, leading to arbitrary code execution on the server.
Users are advised to update Mirasvit Full Page Cache Warmer for Magento 2 to version 1.11.12 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45247 | CISA-ADP | US Government Resource |
| https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/ | CISA-ADP | Third Party Advisory |
| https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer | [email protected] | Release Notes |
| https://sansec.io/research/mirasvit-cache-warmer-object-injection | [email protected] | Third Party Advisory |
| https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection | [email protected] | Third Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability | Jun 3, 2026 | Jun 6, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mirasvit full page cache warmer | < 1.11.12 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 26, 2026 | New CVE Received | [email protected] |