Junglewise Threat Intelligence

CVE-2026-34653: Adobe Commerce path traversal vulnerability

CVE-2026-34653 · Severity: high · CVSS 8.7 · Published 2026-05-12

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used for managing online stores, is affected by a security flaw that allows administrative users to access or modify files they should not be able to reach. An attacker with high-level access could use this to read sensitive configuration data or overwrite critical system files, potentially leading to a full compromise of the store's data and operations. This issue does not require any interaction from other users to be exploited.

Technical details

A path traversal vulnerability (CWE-22) exists in Adobe Commerce due to improper limitation of pathnames to restricted directories. An authenticated attacker with administrative privileges can exploit this flaw over the network without any user interaction. By providing manipulated file paths, the attacker can read or write files outside of the intended directory scope. Because the vulnerability allows for arbitrary file system writes and has a 'Changed' scope (S:C), it could potentially lead to remote code execution or persistent system compromise. Adobe has released security updates to address this issue in the affected versions.

Affected products

  • Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats