Impact
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation requires user interaction: the victim must visit a maliciously crafted URL or interact with a compromised web page, after which the dangerous file can be uploaded and executed. The vulnerability’s scope change indicates that the effect may extend beyond the immediate user to other parts of the application.
Affected Systems
The vulnerability affects Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source from Adobe. No specific affected versions are listed in the CNA data, so all currently supported releases are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 9.3 highlights a critical severity, while an EPSS score of 28% signals a moderate to high likelihood of exploitation in the near term. The issue is not listed in the CISA KEV catalog, but its high severity and exploit probability make it a priority for mitigation. The attack vector is user interaction; an attacker must entice a user to visit a crafted link or compromised page to trigger the file upload that leads to arbitrary code execution.
OpenCVE Enrichment