Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HAdobe Commerce
APPAdobe2.4.42.4.52.4.62.4.72.4.82.4.9Adobe Commerce B2b
APPAdobe1.3.31.3.41.4.21.5.21.5.3Adobe I\/o Events
APPAdobe1.6.0 – 1.21.0 (excl.)Adobe Magento
APPAdobe2.4.62.4.72.4.82.4.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
Related vulnerabilities
CVE-2025-54236CRITICAL9.1⚠ KEVPL ✓same product
Adobe Commerce/Magento — przejęcie sesji przez Improper Input Validation
CVE-2024-34102CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność XXE w Adobe Commerce umożliwiająca RCE
CVE-2022-24086CRITICAL9.8⚠ KEVPL ✓same product
Adobe Commerce — RCE przez błędną walidację danych podczas checkout
CVE-2026-48356CRITICAL9.3PL ✓same product
Adobe Commerce — nieograniczony upload pliku umożliwiający RCE
CVE-2025-24434CRITICAL9.1PL ✓same product
Adobe Commerce — Incorrect Authorization umożliwiające privilege escalation