DIRAS TAKE
Urgent — the flaw permits remote code execution without any login, so prioritize containment and patching actions immediately where ps_facetedsearch is exposed to untrusted networks.
What is CVE-2026-54159?
An unauthenticated attacker can write files and execute code on the ps_facetedsearch module, enabling full remote code execution (CVE-2026-54159). The issue affects ps_facetedsearch versions >= 3.0.0 and < 4.0.4 and can be triggered over the network without authentication or user interaction by supplying a crafted filter value in the request URL.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of PrestaShop ps_facetedsearch are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| ps_facetedsearch | >= 3.0.0, < 4.0.4 |
Is CVE-2026-54159 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-54159
- Remove or restrict public access to the ps_facetedsearch module from the internet until a vendor fix is applied.
- Apply firewall or web application firewall rules to block or inspect requests that modify filter/slider parameters in URLs.
- Monitor webserver and application logs for unexpected file writes inside modules/ps_facetedsearch/ and for new or modified PHP files.
- Follow PrestaShop vendor guidance and install vendor-supplied updates as soon as a patch is released.
Frequently asked questions
Is CVE-2026-54159 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which ps_facetedsearch versions are affected by CVE-2026-54159?
ps_facetedsearch versions greater than or equal to 3.0.0 and less than 4.0.4 are affected.
Is there a patch for CVE-2026-54159?
A fixed version is not listed in the provided facts; follow PrestaShop vendor guidance and install any official fixes when released.
Does CVE-2026-54159 require authentication?
No, the vulnerability can be exploited without authentication or user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54159
- cve.org/CVERecord?id=CVE-2026-54159
- github.com/PrestaShop/ps_facetedsearch/security/advisories/GHSA-m5f5-28qr-9g9r
- github.com/PrestaShop/ps_facetedsearch/commit/9ca839fac68a60641d8187a3ff9730ab09af33cb
- github.com/PrestaShop/ps_facetedsearch/releases/tag/v4.0.4
- All PrestaShop CVEs on CVE Radar
- CVEs published in September 2026