CVE-2026-54159: pre-auth remote code execution in PrestaShop ps_facetedsearch

An unauthenticated attacker can write files and execute code on the ps_facetedsearch module, enabling full remote code execution (CVE-2026-54159). The issue affects ps_facetedsearch versions >= 3.0.0 and < 4.0.4 and can be triggered over the network without authentication or user interaction by supplying a crafted filter value in the request URL.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
10CRITICAL
EPSS
0.0075
CWE
CWE-74
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent — the flaw permits remote code execution without any login, so prioritize containment and patching actions immediately where ps_facetedsearch is exposed to untrusted networks.

What is CVE-2026-54159?

An unauthenticated attacker can write files and execute code on the ps_facetedsearch module, enabling full remote code execution (CVE-2026-54159). The issue affects ps_facetedsearch versions >= 3.0.0 and < 4.0.4 and can be triggered over the network without authentication or user interaction by supplying a crafted filter value in the request URL.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of PrestaShop ps_facetedsearch are affected?

BRANCHAFFECTEDFIXED
ps_facetedsearch>= 3.0.0, < 4.0.4

Is CVE-2026-54159 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-54159

  1. Remove or restrict public access to the ps_facetedsearch module from the internet until a vendor fix is applied.
  2. Apply firewall or web application firewall rules to block or inspect requests that modify filter/slider parameters in URLs.
  3. Monitor webserver and application logs for unexpected file writes inside modules/ps_facetedsearch/ and for new or modified PHP files.
  4. Follow PrestaShop vendor guidance and install vendor-supplied updates as soon as a patch is released.

Frequently asked questions

Is CVE-2026-54159 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which ps_facetedsearch versions are affected by CVE-2026-54159?

ps_facetedsearch versions greater than or equal to 3.0.0 and less than 4.0.4 are affected.

Is there a patch for CVE-2026-54159?

A fixed version is not listed in the provided facts; follow PrestaShop vendor guidance and install any official fixes when released.

Does CVE-2026-54159 require authentication?

No, the vulnerability can be exploited without authentication or user interaction.

References