Description
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 7.2 High
EPSS: 19.9% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce, its B2B extension, Webhooks Plugin and Magento Open Source are vulnerable to an SQL injection caused by improper neutralization of special characters. An attacker who can send specially crafted requests can execute arbitrary SQL commands in the context of the current user. This could lead to elevated privileges, account takeover, or arbitrary code execution, and the vulnerability does not require any user interaction.

Affected Systems

The affected vendors are Adobe, with products Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin and Magento Open Source. No specific version range is supplied in the data, so all current releases may be vulnerable until a fix is available.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, while an EPSS score of 20% shows a relatively high probability of exploitation. The vulnerability is listed outside the CISA KEV catalog. Attackers can exploit it by sending crafted HTTP requests that are processed as SQL code, bypassing any user interaction requirement.

Generated by OpenCVE AI on July 31, 2026 at 05:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source to the latest patched releases that contain the SQL injection fix.
  • If an immediate upgrade is not feasible, reduce database privileges for the application and enforce strict input validation or parameterized queries to prevent SQL injection.
  • Disable the Adobe Commerce Webhooks Plugin until a patched version is released, especially if external data injection is not required.
  • Perform a comprehensive audit of all exposed endpoints for similar injection flaws and apply secure coding practices, such as using prepared statements and escaping.

Generated by OpenCVE AI on July 31, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction.
Title Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Adobe Commerce Webhooks Plugin Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T10:27:34.223Z

Reserved: 2026-05-20T15:50:31.367Z

Link: CVE-2026-47992

cve-icon Vulnrichment

Updated: 2026-07-15T10:27:29.513Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:53:19Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')