Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a critical security vulnerability. An attacker could exploit this flaw to execute unauthorized commands on the server, potentially leading to a full system takeover or theft of sensitive customer data. While the attack requires high-level administrative privileges, it does not require any interaction from other users to succeed.
Technical details
Adobe Commerce and Magento Open Source are vulnerable to arbitrary code execution due to improper encoding or escaping of output (CWE-116). The vulnerability allows a remote attacker with high-level administrative privileges (PR:H) to execute arbitrary code in the context of the current user. The attack is delivered over the network and does not require user interaction, but it results in a changed scope (S:C), indicating the impact may extend beyond the vulnerable component to the underlying host or other integrated systems. Adobe has released patches to address this issue across multiple versions of Commerce, Magento, and the Webhooks Plugin.
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory