Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security vulnerability that could allow an attacker to execute unauthorized database commands. An attacker with high-level administrative privileges could exploit this flaw to gain full control over the system, potentially leading to the theft of customer data or complete service disruption. This issue can be exploited remotely without any interaction from other users.
Technical details
An SQL injection vulnerability (CWE-89) exists in Adobe Commerce, Magento Open Source, and related components due to improper neutralization of special elements in SQL commands. The vulnerability is reachable over the network and requires high-privileged administrative credentials to exploit (PR:H). Successful exploitation allows an attacker to execute arbitrary SQL commands, which Adobe notes could lead to arbitrary code execution in the context of the current user. No user interaction is required for exploitation. Patches have been released in the July 2026 update cycle (e.g., version 2.4.9-2026-jul).
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory