Impact
Adobe Commerce and its variants are affected by a path‑traversal flaw that allows an attacker possessing elevated privileges to read or modify files outside the intended protected directories. This bypasses security controls and can result in limited disruption of availability, but the primary consequence is the unauthorized disclosure of configuration or other sensitive files.
Affected Systems
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are all listed as affected. Version information is not provided in the advisory; administrators should verify that their installations are not among the specified vulnerable releases by consulting the linked Adobe advisory.
Risk and Exploitability
The CVSS score of 7.6 classifies the vulnerability as high severity, and since exploitation does not require user interaction, an attacker with local or remote high privileges can trigger it directly. The EPSS score indicates a very low probability of active exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves the attacker gaining elevated privileges on the host platform, and then supplying a crafted pathname that escapes the restricted directory constraint, leading to unauthorized file access and potential further compromise.
OpenCVE Enrichment