Vulnerability record · CVE-2019-12799 · published 13 June 2019
CVE-2019-12799: Shopware PHP object instantiation flaw enables deserialization RCE
Shopware · Shopware
Shopware through 5.6.x contains a PHP object instantiation flaw in createInstanceFromNamedArguments that a crafted web request can trigger, leading to arbitrary deserialization when a suitable class is instantiated. It is a bypass of the whitelist patch for CVE-2017-18357, so the earlier fix does not stop this variant. Successful exploitation can result in remote code execution.
Description
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS plus public exploit tooling make this a serious RCE risk, though it requires low privileges and is not in KEV.
What it is
Shopware through 5.6.x contains a PHP object instantiation flaw in createInstanceFromNamedArguments that a crafted web request can trigger, leading to arbitrary deserialization when a suitable class is instantiated. It is a bypass of the whitelist patch for CVE-2017-18357, so the earlier fix does not stop this variant. Successful exploitation can result in remote code execution.
Impact
An attacker who can reach the vulnerable code path can instantiate attacker-influenced classes and deserialize untrusted data, ultimately executing arbitrary code on the server. That gives full compromise of the Shopware application and its host, including data and integrity of the store.
Attack surface
Reached over the network via a crafted web request to the affected Shopware endpoint; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). No specific endpoint or parameter is named in the record.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.55 (99th percentile), and a Metasploit pull request reference indicates public exploit tooling exists. No ransomware usage is documented.
What to do
- Upgrade Shopware to a version after 5.6.x that contains the fix for this bypass; patch first.
- If immediate upgrade is not possible, restrict network access to the affected Shopware endpoints and require authentication where feasible.
- Review and harden the deserialization whitelist logic so the CVE-2017-18357 bypass class cannot be instantiated.
- Monitor for and block requests attempting to supply serialized object payloads to Shopware parameters.
- Apply WAF or virtual patching rules targeting PHP object injection patterns until the upgrade is complete.
Detection
- Search web and application logs for requests containing serialized PHP object strings (e.g., O: or a: patterns) in parameters to Shopware endpoints.
- Alert on unexpected outbound connections or child processes spawned by the PHP/web server process.
- Monitor for file writes or new files in web-accessible directories following Shopware requests.
- Use the Metasploit module reference to build signatures for known exploit request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/rapid7/metasploit-framework/pull/11828 | Issue TrackingPatchThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/11828 | Issue TrackingPatchThird Party Advisory |
Track CVE-2019-12799 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12799), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.