CVE-2026-21360
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-21360 is a path traversal vulnerability (CWE-22) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows a high-privileged authenticated attacker to access unauthorized files or directories outside the intended restricted path, resulting in a security feature bypass. The vulnerability was disclosed on March 10–11, 2026, as part of Adobe's APSB26-05 security bulletin. Affected versions include Adobe Commerce 2.4.4 through 2.4.4-p16, 2.4.5 through 2.4.5-p15, 2.4.6 through 2.4.6-p13, 2.4.7 through 2.4.7-p8, 2.4.8 through 2.4.8-p3, and 2.4.9-alpha3, along with corresponding Commerce B2B and Magento Open Source releases. It carries a CVSS v3.1 base score of 6.8 (Medium) (Adobe Advisory).

Technical details

The root cause is an Improper Limitation of a Pathname to a Restricted Directory (CWE-22), commonly known as path traversal. An attacker with high-level administrative privileges can craft requests that traverse outside the intended directory boundaries, bypassing file access restrictions enforced by the application. The attack is network-based, requires no user interaction, and has a changed scope, meaning the impact can extend beyond the vulnerable component itself. No public proof-of-concept or detailed technical write-up has been identified at this time (Adobe Advisory).

Impact

Successful exploitation allows a high-privileged attacker to read unauthorized files or directories on the server, resulting in a high confidentiality impact with no integrity or availability impact. The changed scope indicates that the attacker may be able to access resources beyond the Commerce application's own security domain, potentially exposing sensitive configuration files, credentials, or customer data stored on the underlying server. While the vulnerability does not directly enable code execution or data modification, unauthorized file access could facilitate further attacks such as credential harvesting or lateral movement (Adobe Advisory).

Mitigation and workarounds

Adobe has released patched versions addressing CVE-2026-21360 as part of the APSB26-05 bulletin published March 10, 2026. Administrators should upgrade to the following fixed versions or later: Adobe Commerce 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4 (or 2.4.9 GA); corresponding Commerce B2B and Magento Open Source releases should also be updated per the advisory. As an interim measure, restrict administrative panel access to trusted IP addresses and enforce the principle of least privilege for admin accounts. Regularly audit admin user accounts and monitor for anomalous file access patterns (Adobe Advisory).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution and security feature bypass, recommending prompt patching (CIS Advisory). Community aggregators such as CVEFeed and VulDB indexed the vulnerability shortly after disclosure, and it received routine coverage from security news outlets. No notable researcher commentary or significant social media discussion specific to CVE-2026-21360 has been identified beyond standard vulnerability tracking (Adobe Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48358CRITICAL10
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48356CRITICAL9.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48000MEDIUM6.1
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48371MEDIUM5.4
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48001LOW3.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management