Description
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Published: 2026-07-14
Score: 9.3 Critical
EPSS: 28.2% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation requires user interaction: the victim must visit a maliciously crafted URL or interact with a compromised web page, after which the dangerous file can be uploaded and executed. The vulnerability’s scope change indicates that the effect may extend beyond the immediate user to other parts of the application.

Affected Systems

The vulnerability affects Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source from Adobe. No specific affected versions are listed in the CNA data, so all currently supported releases are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 9.3 highlights a critical severity, while an EPSS score of 28% signals a moderate to high likelihood of exploitation in the near term. The issue is not listed in the CISA KEV catalog, but its high severity and exploit probability make it a priority for mitigation. The attack vector is user interaction; an attacker must entice a user to visit a crafted link or compromised page to trigger the file upload that leads to arbitrary code execution.

Generated by OpenCVE AI on August 3, 2026 at 03:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security patch or upgrade to a version where Adobe Commerce has fixed the file upload restriction flaw.
  • Restrict uploads to approved file types on the application level, ensuring that files with dangerous extensions such as .php, .js, or other executables are rejected.
  • Deploy a Web Application Firewall or similar controls to monitor and block suspicious upload attempts, providing an additional layer of defense while a patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed. Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}

cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Title Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Adobe Commerce Webhooks Plugin Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-21T21:34:31.760Z

Reserved: 2026-05-21T15:28:38.140Z

Link: CVE-2026-48356

cve-icon Vulnrichment

Updated: 2026-07-15T10:27:16.485Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:53:07Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type