← Vulnerability feed

Vulnerability record · CVE-2019-12799 · published 13 June 2019

CVE-2019-12799: Shopware PHP object instantiation flaw enables deserialization RCE

Shopware · Shopware

Shopware through 5.6.x contains a PHP object instantiation flaw in createInstanceFromNamedArguments that a crafted web request can trigger, leading to arbitrary deserialization when a suitable class is instantiated. It is a bypass of the whitelist patch for CVE-2017-18357, so the earlier fix does not stop this variant. Successful exploitation can result in remote code execution.

8.8 CVSS 3.1 High EPSS 55% · top 1.0% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 6.5
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and high EPSS plus public exploit tooling make this a serious RCE risk, though it requires low privileges and is not in KEV.

What it is

Shopware through 5.6.x contains a PHP object instantiation flaw in createInstanceFromNamedArguments that a crafted web request can trigger, leading to arbitrary deserialization when a suitable class is instantiated. It is a bypass of the whitelist patch for CVE-2017-18357, so the earlier fix does not stop this variant. Successful exploitation can result in remote code execution.

Impact

An attacker who can reach the vulnerable code path can instantiate attacker-influenced classes and deserialize untrusted data, ultimately executing arbitrary code on the server. That gives full compromise of the Shopware application and its host, including data and integrity of the store.

Attack surface

Reached over the network via a crafted web request to the affected Shopware endpoint; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). No specific endpoint or parameter is named in the record.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.55 (99th percentile), and a Metasploit pull request reference indicates public exploit tooling exists. No ransomware usage is documented.

What to do

  • Upgrade Shopware to a version after 5.6.x that contains the fix for this bypass; patch first.
  • If immediate upgrade is not possible, restrict network access to the affected Shopware endpoints and require authentication where feasible.
  • Review and harden the deserialization whitelist logic so the CVE-2017-18357 bypass class cannot be instantiated.
  • Monitor for and block requests attempting to supply serialized object payloads to Shopware parameters.
  • Apply WAF or virtual patching rules targeting PHP object injection patterns until the upgrade is complete.

Detection

  • Search web and application logs for requests containing serialized PHP object strings (e.g., O: or a: patterns) in parameters to Shopware endpoints.
  • Alert on unexpected outbound connections or child processes spawned by the PHP/web server process.
  • Monitor for file writes or new files in web-accessible directories following Shopware requests.
  • Use the Metasploit module reference to build signatures for known exploit request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/rapid7/metasploit-framework/pull/11828 Issue TrackingPatchThird Party Advisory
https://github.com/rapid7/metasploit-framework/pull/11828 Issue TrackingPatchThird Party Advisory

Track CVE-2019-12799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-42355Shopware code injection vulnerabilityShopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Pr…EPSS 0.86%9.8CVE-2024-42357Shopware sql injection vulnerabilityShopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which ena…EPSS 0.60%9.8CVE-2024-22406Shopware sql injection vulnerabilityShopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through in…EPSS 0.64%9.8CVE-2023-22732Shopware insufficient session expiration vulnerabilityShopware is an open source commerce platform based on Symfony Framework and Vue js. The Administration session expiration was set to one week, when a…EPSS 0.73%9.8CVE-2021-37708Shopware command injection vulnerabilityShopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.…EPSS 2.4%9.8CVE-2016-3109Shopware improper input validation vulnerabilityThe backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.EPSS 28%8.9CVE-2026-31889Shopware authentication bypass by spoofing vulnerabilityShopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specif…EPSS 0.41%8.9CVE-2026-31887Shopware incorrect authorization vulnerabilityShopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows…EPSS 0.39%

Source: NIST National Vulnerability Database (record CVE-2019-12799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.