Executive brief
Adobe Commerce, a popular e-commerce platform used for online storefronts, is vulnerable to a critical security flaw that allows attackers to upload dangerous files. If exploited, an attacker could execute malicious code on the server or within a user's browser session, potentially leading to full account takeover or unauthorized access to customer data. This attack requires a victim to interact with a malicious link or a compromised web page.
Technical details
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) within Adobe Commerce and Magento Open Source. It allows a remote attacker to upload malicious files that can lead to arbitrary code execution. The attack vector is network-based and does not require administrative privileges, though it does require user interaction (UI:R), such as a victim visiting a specifically crafted URL. Because the vulnerability results in a scope change (S:C), the impact can extend beyond the immediate component to the user's session or the underlying server environment. Adobe has released patches to address this issue in the July 2026 update cycle.
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory