
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48356 is a critical Unrestricted Upload of File with Dangerous Type vulnerability (CWE-434) in Adobe Commerce, Magento Open Source, Adobe Commerce B2B, and Adobe Commerce Events. It allows unauthenticated remote attackers to achieve arbitrary code execution in the context of the current user by tricking a victim into visiting a maliciously crafted URL or interacting with a compromised web page. Affected versions include Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier; Adobe Commerce B2B 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier; Magento Open Source 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, and 2.4.6-p15 and earlier; and Adobe Commerce Events versions 1.6.0 through 1.20.0. The vulnerability was disclosed and patched on July 14, 2026, with a CVSS v3.1 base score of 9.6 (Critical) (Adobe Advisory, GitHub Advisory).
The root cause is improper restriction of uploaded file types (CWE-434), allowing dangerous file types to be uploaded and automatically processed by the server environment. The attack vector is network-based, requiring no privileges but requiring user interaction — a victim must visit a maliciously crafted URL or interact with a compromised web page. Once triggered, the vulnerability enables an attacker to upload malicious files (e.g., PHP web shells or scripts) that execute arbitrary code within the web server context, with scope change indicating the impact extends beyond the vulnerable component's security boundary to affect other resources such as the victim's session or account. No public proof-of-concept code has been reported as of the disclosure date (Adobe Advisory, GitHub Advisory).
Successful exploitation results in arbitrary code execution in the context of the current user, with high confidentiality and integrity impact and low availability impact. An attacker can inject malicious scripts into web pages, gain elevated access or control over the victim's account or session, and potentially pivot to other resources within the affected environment due to the changed scope. The combination of no required privileges and a changed scope makes this vulnerability particularly dangerous for e-commerce environments handling sensitive customer and payment data (Adobe Advisory, GitHub Advisory).
No public proof-of-concept exploit code has been reported, and there is no evidence of in-the-wild exploitation as of the disclosure date (Adobe Advisory). The EPSS score is approximately 17.9–28.2% (98th percentile per GitHub Advisory), indicating a relatively elevated probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD SSVC assessment classifies exploitation as "none" at time of analysis, though the high EPSS score warrants close monitoring (GitHub Advisory).
.php, .phtml, .php5) in the uploaded filename; outbound connections from the web server to unknown external IPs following file upload activity.pub/media/, pub/static/, or custom upload directories); newly created files with web shell signatures (e.g., eval(base64_decode, system(, passthru().apache, nginx, php-fpm) such as bash, curl, wget, or network utilities; unexpected cron jobs or scheduled tasks created under the web server user account.Adobe released security updates on July 14, 2026, addressing this vulnerability across all affected product lines. Administrators should update to the July 2026 patched releases: for Adobe Commerce, apply the July 2026 security update for the applicable branch (2.4.4 through 2.4.9); for Magento Open Source, apply the July 2026 update for branches 2.4.6 through 2.4.9; for Adobe Commerce B2B, apply the July 2026 patch for the applicable branch (1.3.3 through 1.5.3); and for Adobe Commerce Events, upgrade to version 1.21.0 or later. No vendor-provided configuration workaround is documented; upgrading to a patched version is the recommended and only confirmed remediation (Adobe Advisory).
The vulnerability was covered by multiple security news outlets including SecurityWeek, The Hacker News, The Register, and CSOOnline as part of broader July 2026 Patch Tuesday coverage, noting Adobe's release of critical fixes across multiple products. CIS Security issued an advisory noting multiple Adobe product vulnerabilities could allow arbitrary code execution. The high EPSS score (98th percentile) drew attention from threat intelligence platforms including Feedly and Check Point, which published defensive advisories shortly after disclosure. The e-commerce security community highlighted the risk to Magento store operators, with at least one dedicated blog post urging immediate patching (Adobe Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."