Executive brief
Adobe Commerce, a widely-used e-commerce platform, contains a path traversal vulnerability that allows an attacker with administrative privileges to access files and directories outside the intended restrictions. This could enable unauthorized access to sensitive business data, configuration files, or other protected resources, undermining the platform's security controls and potentially exposing customer or operational information.
Technical details
The vulnerability is a path traversal (directory traversal) flaw in Adobe Commerce that fails to properly restrict pathname access to designated directories. An attacker with high-level privileges can manipulate file paths to navigate outside intended restrictions and access unauthorized files or directories. The vulnerability changes the security scope and bypasses existing access controls. No user interaction is required for exploitation, and the attack vector is likely internal or administrative in nature given the privilege requirement. Patches are expected to be available from Adobe.
Affected products
- Adobe Commerce
Timeline
- 2026-09-08: disclosed