Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NAdobe Commerce
APPAdobe2.4.42.4.52.4.62.4.72.4.82.4.9Adobe Commerce B2b
APPAdobe1.3.31.3.41.4.21.5.21.5.3Adobe I\/o Events
APPAdobe1.6.0 – 1.21.0 (excl.)Adobe Magento
APPAdobe2.4.62.4.72.4.82.4.9
Related vulnerabilities
Adobe Commerce/Magento — przejęcie sesji przez Improper Input Validation
Krytyczna podatność XXE w Adobe Commerce umożliwiająca RCE
Adobe Commerce — RCE przez błędną walidację danych podczas checkout
RCE w Adobe Commerce — błąd kodowania wyjścia (CVE-2026-48358)
Adobe Commerce — Incorrect Authorization umożliwiające privilege escalation