Vulnerability record · CVE-2016-4010 · published 23 January 2017
CVE-2016-4010: Magento PHP object injection in shopping cart data enables RCE
MMagento · Magento
Magento CE and EE before 2.0.6 unserialize crafted shopping cart data without adequate validation, allowing PHP object injection. An attacker can chain that injection into arbitrary PHP code execution on the server. The flaw is remotely reachable and needs no credentials, so any exposed storefront is a candidate target.
Description
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, very high EPSS and public exploit code makes this an urgent patch target.
What it is
Magento CE and EE before 2.0.6 unserialize crafted shopping cart data without adequate validation, allowing PHP object injection. An attacker can chain that injection into arbitrary PHP code execution on the server. The flaw is remotely reachable and needs no credentials, so any exposed storefront is a candidate target.
Impact
An attacker gains remote code execution on the Magento host, which typically means full control of the application, its data and the underlying server. That can expose customer records, payment data and administrative access.
Attack surface
Reached over the network through crafted serialized shopping cart data submitted to the storefront; the CVSS vector shows no privileges and no user interaction required. No authentication is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.92869 (99.8th percentile) and multiple references are tagged Exploit, including Packet Storm and Exploit-DB entries, indicating public exploit code exists.
What to do
- Upgrade Magento CE/EE to 2.0.6 or later, or apply the vendor security patch referenced in the Magento advisory.
- If immediate patching is not possible, restrict or block untrusted serialized input reaching cart handling code and tighten WAF rules around cart endpoints.
- Remove or harden any unused cart, API or admin endpoints exposed to the internet.
- Rotate credentials and secrets stored on the Magento host if compromise is suspected, and review file integrity on the web root.
Detection
- Monitor web logs for POST requests to cart endpoints carrying serialized PHP object payloads (O: or a: patterns) or unusually long encoded parameters.
- Alert on unexpected PHP file creation or modification under the Magento web root, which is consistent with the arbitrary file write described in public exploit write-ups.
- Watch for outbound connections or child processes spawned by the web server user that are not normal for Magento.
- Correlate requests from a single source hitting cart endpoints repeatedly with malformed or oversized payloads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-4010 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-4010), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.