CVE-2026-54159Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal filter-block cache where it is serialized and later read back with a raw native unserialize() in src/Filters/Block.php. By crafting that value, an unauthenticated attacker can smuggle a malicious serialized PHP object into the cache, and when it is deserialized, a gadget chain writes an arbitrary PHP file inside the modules/ps_facetedsearch/ directory, which is then used as a webshell to run commands on the server. This issue is fixed in version 4.0.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-11); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-10: 1Mentions · 2026-07-11: 2Mentions · 2026-07-12: 1Mentions · 2026-10-08: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-11: 2Technical Details · 2026-07-12: 107-1007-1107-1210-08
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-101
Disclosure1
2026-07-112
Disclosure2
2026-07-121
Disclosure1
Full discourse5 posts
  • CERT@certlv

    ‼️ Satura vadības sistēmas PrestaShop modulī ps_facetedsearch ir atklāta kritiska ievainojamība (CVE-2026-54159), kas ļauj neautentificētam uzbrucējam patvaļīgi izpildīt PHP kodu. Aicinām uzstādīt atjauninājumus! https://cert.lv/lv/2026/10/kritiska-drosibas-ievainojamiba-prestashop-moduli https://t.co/rSwlgOMmBM

    01021619
    5.7K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🛒 PrestaShop shops, heads up. CVE-2026-54159 is a critical PHP Object Injection in ps_facetedsearch — triggered via a crafted slider filter in the URL. CVSS 10, no auth required, full RCE potential. Check your module version now. #PrestaShop #infosec https://secalerts.co/vulnerability/CVE-2026-54159?utm_campaign=x https://t.co/fun6IV1b9m

    Post summary

    PrestaShop’s ps_facetedsearch module is vulnerable to CVE-2026-54159, a critical PHP Object Injection that allows unauthenticated remote code execution via a crafted URL slider filter.

    00000127
    858 followersView on X
  • infosec.@inf0secc
    Disclosure

    One unauthenticated request could lead to full server compromise. CVE-2026-54159 is a critical vulnerability affecting PrestaShop’s "ps_facetedsearch" module. The vulnerable data flow was particularly interesting: User-controlled slider value → stored in an internal cache → processed using native "unserialize()" → PHP Object Injection → gadget chain → arbitrary PHP file write and remote code execution The affected value originated from price or weight filters exposed through the storefront. Because it was not sufficiently validated before reaching the serialized cache, an unauthenticated attacker could potentially compromise the shop and its underlying server. The deeper lesson is not limited to PHP: A cache is not a trust boundary. Attacker-controlled data does not become trusted simply because it was stored, serialized or processed by an internal component. Defensive takeaways: • Avoid native deserialization of attacker-influenced data • Enforce strict type and format validation before caching • Trace data across storage boundaries during secure code review • Treat plugins and modules as part of the application’s attack surface • Upgrade "ps_facetedsearch" to version 4.0.4 This is why effective AppSec requires following the complete data flow—not only reviewing the endpoint that initially receives the input. #AppSec

    Post summary

    The post announces CVE-2026-54159, detailing a PHP Object Injection flaw that can lead to remote code execution, and recommends upgrading to v4.0.4 to mitigate the risk.

    0000098
    67 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated PHP Object Injection leading to Webshell RCE (CVE-2026-54159) A PHP object injection flaw in the PrestaShop module ps_facetedsearch lets attacker-controlled price/weight slider values from the URL get stored into a serialized cache and later processed. The root cause is unsafe deserialization via a raw unserialize() on untrusted data, enabling a PHP object injection gadget chain. An unauthenticated attacker can exploit this remotely by sending crafted filter parameters in requests, waiting for the cache to be deserialized during normal module operation. Successful exploitation enables arbitrary PHP file write in the module directory and remote code execution via a webshell, leading to full compromise of the shop and underlying server. 👉 Affected: prestashop/ps_facetedsearch (versions TBD; vulnerable builds prior to vendor fix) | Upgrade to No fix yet - treat as suspicious

    Post summary

    A critical PrestaShop ‘ps_facetedsearch’ module flaw allows unauthenticated attackers to inject objects, leading to remote code execution through a webshell. No patch is available yet, making immediate mitigation essential.

    00000127
    247 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PrestaShop ps_facetedsearch Module, PHP Object Injection, #CVE-2026-54159 (Critical) -DC-Jul2026-873 https://dailycve.com/prestashop-ps_facetedsearch-module-php-object-injection-cve-2026-54159-critical-dc-jul2026-873/

    Post summary

    A brief alert highlights a critical PHP Object Injection flaw in PrestaShop’s ps_facetedsearch module (CVE‑2026‑54159), without detail on PoC, exploitation, or remediation.

    0000055
    218 followersView on X

Explore more