Insecure Deserialization Vulnerability in TrueLayer Magento 2 Plugin
CVE-2026-103831

7.5HIGH

Key Information:

Vendor

Truelayer

Vendor
CVE Published:
6 October 2026

What is CVE-2026-103831?

The Psr16CacheAdapter component in the TrueLayer Magento 2 Plugin contains a vulnerability due to the insecure use of PHP's native unserialize() function. This flaw allows an attacker with write access to the cache backend—commonly Redis or Memcached—to inject manipulated data, potentially triggering the deserialization of specially crafted PHP objects. This exploitation may lead to arbitrary code execution based on gadget strings present in the application environment. This vulnerability emphasizes the necessity for robust input validation and restricted handling of deserialized data to prevent unauthorized access and code execution risks.

Affected Version(s)

TrueLayer Magento 2 Plugin versions 2.4.0 through 2.4.2.

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gemma López Jiménez
Víctor Flores Sánchez
.