OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-85520

CRITICAL · CVSS 9.3 EPSS 0.99% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Google Merchant Center Feed module for PrestaShop is vulnerable to unauthenticated arbitrary file write via the feed.php endpoint, allowing attackers to manipulate file names, paths, and content through crafted requests. This critical vulnerability can lead to remote code execution, enabling attackers to execute arbitrary PHP code on the server. PrestaShop users, particularly those utilizing the affected module, should prioritize updating to version 2.3.9 to mitigate this severe risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85520
Severity
CRITICAL
CVSS
9.3
EPSS
0.99%

Original NVD Description

Google Merchant Center Feed (gmfeed) module for PrestaShop is vulnerable to unauthenticated arbitrary file write in the feed.php endpoint. An unauthenticated attacker can send a crafted request that controls the output file name, path, extension, and content through request parameters. Due to the lack of authentication and input validation, the request is processed successfully, allowing an attacker to write and execute arbitrary PHP code, resulting in remote code execution (RCE). This issue was fixed in version 2.3.9.