Junglewise Threat Intelligence

CVE-2026-48356: Adobe Commerce unrestricted file upload in multiple components

CVE-2026-48356 · Severity: critical · CVSS 9.6 · Published 2026-07-14

Executive brief

Adobe Commerce, a popular e-commerce platform used for online storefronts, is vulnerable to a critical security flaw that allows attackers to upload dangerous files. If exploited, an attacker could execute malicious code on the server or within a user's browser session, potentially leading to full account takeover or unauthorized access to customer data. This attack requires a victim to interact with a malicious link or a compromised web page.

Technical details

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type) within Adobe Commerce and Magento Open Source. It allows a remote attacker to upload malicious files that can lead to arbitrary code execution. The attack vector is network-based and does not require administrative privileges, though it does require user interaction (UI:R), such as a victim visiting a specifically crafted URL. Because the vulnerability results in a scope change (S:C), the impact can extend beyond the immediate component to the user's session or the underlying server environment. Adobe has released patches to address this issue in the July 2026 update cycle.

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats