Impact
The flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source allows injection of malicious template content that is evaluated by the system, enabling execution of arbitrary code with the privileges of the current user. It is an improper neutralization of special elements used in the template engine (CWE‑1336). An attacker can trigger the vulnerability without user interaction and the affected software can change scope, potentially elevating privileges beyond the originating user.
Affected Systems
Affected product families are Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The vulnerability applies to Adobe Commerce releases 2.4.4 through 2.4.9 (including all patch iterations and beta/alpha variants), to Adobe Commerce B2B versions 1.3.3 through 1.5.3 (with all sub‑release variants), and to Magento Open Source 2.4.6 through 2.4.9 (including community and beta releases). Earlier releases in each family are not listed as affected.
Risk and Exploitability
The CVSS score is 10, marking the highest severity. The EPSS score of 4% indicates a measurable, albeit low, likelihood of exploitation. The CVE is listed in the CISA KEV catalog, confirming that known threat actors have successfully exploited it. Together these factors mean the vulnerability presents an immediate, high‑priority risk that warrants urgent action.
OpenCVE Enrichment