# Unauthenticated RCE in PrestaShop MyPresta Module

Published: 2026-09-29 · Severity: routine · Sectors: retail, technology
Canonical: https://vorant.io/reports/86faf57c-340d-5c3b-80e1-751e71dd1dd7/unauthenticated-rce-in-prestashop-mypresta-module

> CVE-2026-85520 lets unauthenticated attackers write and execute arbitrary PHP via feed.php in the MyPresta Google Merchant Center Feed module for PrestaShop; fixed in v2.3.9.

CERT Polska coordinated disclosure of a critical vulnerability in the MyPresta Google Merchant Center Feed (gmfeed) module for PrestaShop, an e-commerce platform. The flaw resides in the feed.php endpoint, which accepts unauthenticated requests that let an attacker control the output file's name, path, extension, and content through request parameters. Because the endpoint lacks authentication and proper input validation, an attacker can write a file with a .php extension containing malicious code to a web-accessible location and then execute it, achieving remote code execution on the underlying server.

This is an arbitrary file write leading to RCE — a high-impact vulnerability class for any online store running the affected module, since successful exploitation gives full control of the web application (and potentially the host) without any credentials. The vendor fixed the issue in version 2.3.9. There is no indication in this advisory that the vulnerability is being exploited in the wild; it was reported and coordinated through CERT Polska's responsible disclosure process, credited to Today Group sp. z o.o.

Defenders running PrestaShop with the MyPresta gmfeed module should upgrade to version 2.3.9 or later immediately. Where immediate patching isn't possible, restrict or disable public access to feed.php, monitor for unexpected .php files being written to web-accessible directories, and review web server logs for anomalous requests to the feed.php endpoint with suspicious file path/extension parameters.

## Mentioned in this report

- Vulnerabilities: CVE-2026-85520

## Detection guidance (public sample)

### Suspicious PHP File Creation in Web Root

ATT&CK: T1190

Detects creation of .php files in web-accessible directories (modules, uploads, feeds) via web server process, suggestive of web shell upload/write via exploit. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Suspicious PHP File Creation in Web Root
description: Monitors for .php file creation in PrestaShop web-accessible paths (modules/,
  uploads/, feeds/) by web server processes (apache, nginx, php-fpm), characteristic
  of arbitrary file write exploitation.
tags:
- attack.t1190
- attack.t1505.003
logsource:
  category: file_event
  product: windows
detection:
  selection:
    Image|endswith:
    - \apache.exe
    - \httpd.exe
    - \nginx.exe
    - \php-cgi.exe
    - \php.exe
    TargetFilename|contains:
    - \modules\
    - \uploads\
    - \feeds\
    TargetFilename|endswith: .php
  filter_module_install:
    TargetFilename|contains: \modules\ps_
  condition: selection and not filter_module_install
falsepositives:
- Legitimate module uploads via PrestaShop admin interface
- Automated module installation/updates from trusted package sources
level: high
id: 0b802e89-813e-54c2-a919-b5e0973d2fb9
status: experimental
author: Vorant
references:
- https://cert.pl/en/posts/2026/09/CVE-2026-85520
```

### Suspicious PHP File Creation in Web Root (Linux)

ATT&CK: T1190

Detects creation of .php files in web-accessible directories via web server processes on Linux, characteristic of web shell deployment. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Suspicious PHP File Creation in Web Root (Linux)
description: Monitors for .php file creation in PrestaShop web-accessible paths by
  web server processes (apache, nginx, php-fpm) on Linux, indicative of arbitrary
  file write exploitation.
tags:
- attack.t1190
- attack.t1505.003
logsource:
  category: file_event
  product: linux
detection:
  selection:
    Image|endswith:
    - /apache
    - /apache2
    - /httpd
    - /nginx
    - /php-fpm
    - /php
    TargetFilename|contains:
    - /modules/
    - /uploads/
    - /feeds/
    TargetFilename|endswith: .php
  filter_module_install:
    TargetFilename|contains: /modules/ps_
  condition: selection and not filter_module_install
falsepositives:
- Legitimate module uploads via PrestaShop admin interface
- Automated module installation/updates from trusted package sources
level: high
id: f57ce0cf-1f95-52a6-b187-35e48d09a16c
status: experimental
author: Vorant
references:
- https://cert.pl/en/posts/2026/09/CVE-2026-85520
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-85520

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/86faf57c-340d-5c3b-80e1-751e71dd1dd7/unauthenticated-rce-in-prestashop-mypresta-module.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
