Impact
An exploit in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source allows an attacker to inject malicious template content that the system evaluates, leading to the execution of arbitrary code with the privileges of the current user. The vulnerability is an improper neutralization of special elements used in the template engine, classified as CWE‑1336. Because the flaw can be triggered without any user interaction and the affected software marks the scope as changed, an attacker may potentially gain a higher privilege level than the original user within the application.
Affected Systems
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected. No specific product version numbers are disclosed in the announcement, so all installations of these products remain potentially vulnerable until patched.
Risk and Exploitability
The security score of 10, the highest possible CVSS rating, signals that exploitation would have catastrophic consequences. While the EPSS score is not available, the lack of user interaction support and the scope change indicate a high likelihood that motivated adversaries could craft an automated attack. The vulnerability is not currently listed in the CISA KEV catalog, but the severity and potential impact recommend treating it as a critical threat.
OpenCVE Enrichment