Deserialization of Untrusted Data in Full Page Cache Warmer for Magento 2 - CVE-2026-45247
Published: June 4, 2026
Full Page Cache Warmer for Magento 2
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in the CacheWarmer cookie handling plugin when processing storefront requests with a crafted CacheWarmer cookie. A remote attacker can send a specially crafted cookie to execute arbitrary code.
No authentication, admin session, or configuration toggle is required, and exploitation may require a suitable gadget chain from Magento or its dependencies.
How to mitigate CVE-2026-45247
Sources
- https://mirasvit.com/package/changelog/?package=mirasvit/module-cache-warmer
- https://sansec.io/research/mirasvit-cache-warmer-object-injection
- https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45247
- https://www.imperva.com/blog/imperva-customers-protected-against-cve-2026-45247-in-mirasvit-full-page-cache-warmer-for-magento/