
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77110 is a Path Traversal vulnerability (CWE-22) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an attacker with high privileges to bypass security restrictions and access unauthorized files or directories outside intended boundaries. The vulnerability was published on September 8, 2026, with a patch made available on September 9, 2026. Affected products include Adobe Commerce versions 2.4.4 through 2.4.9 (and all patch releases within those lines), Adobe Commerce B2B versions 1.3.3 through 1.5.3, and Magento Open Source versions 2.4.6 through 2.4.9. It carries a CVSS v3.1 base score of 7.6 (High) with changed scope (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and arises from insufficient validation of file path inputs within Adobe Commerce's administrative functionality. An attacker with high privileges can craft requests that traverse directory boundaries using path manipulation techniques (e.g., ../ sequences or URL-encoded variants), bypassing the application's intended file system restrictions. Exploitation requires no user interaction and is conducted over the network, with the changed scope indicating that the impact extends beyond the vulnerable component itself. Attack patterns associated with this vulnerability include CAPEC-126 (Path Traversal), CAPEC-64 (Using Slashes and URL Encoding to Bypass Validation), and CAPEC-76 (Manipulating Web Input to File System Calls) (Feedly).
Successful exploitation allows a high-privileged attacker to read or modify files and directories outside the intended restricted paths within the Adobe Commerce installation, resulting in a security feature bypass with high integrity impact and low availability impact. Confidentiality impact is rated as none per the CVSS scoring, though unauthorized file access could expose sensitive configuration data depending on the files reached. The changed scope indicates that resources beyond the vulnerable component — such as the underlying server file system — may be affected, potentially enabling further compromise of the hosting environment (Adobe Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00775 (~0.78%), indicating a low probability of exploitation in the near term. Exploitation requires high privileges (administrative access), which significantly limits the attacker pool.
../../, URL-encoded variants (%2e%2e%2f), or double-encoded forms to bypass input validation.../, %2e%2e, %252e%252e) in parameters; unexpected outbound connections from the Commerce server following admin activity.env.php, config.php) not corresponding to legitimate admin changes.apache, nginx, php-fpm) accessing directories outside the application root.Adobe has released security patches addressing this vulnerability as part of the September 2026 security update (APSB26-138). Administrators should update to the September 2026 patch releases for their respective product lines: Adobe Commerce 2.4.4-2026-sep, 2.4.5-2026-sep, 2.4.6-2026-sep, 2.4.7-2026-sep, 2.4.8-2026-sep, or 2.4.9-2026-sep; Adobe Commerce B2B 1.3.3-2026-sep, 1.3.4-2026-sep, 1.4.2-2026-sep, 1.5.2-2026-sep, or 1.5.3-2026-sep; and Magento Open Source equivalent September 2026 releases. As interim mitigations, restrict administrative access to only authorized personnel, enforce strong authentication (MFA) on admin accounts, and monitor file system access patterns from administrative sessions (Adobe Advisory, Feedly).
The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution and security bypasses, referencing the September 2026 Adobe patch batch (CIS Advisory). AusCERT published bulletin ESB-2026.10690 covering the Adobe September 2026 releases. No significant independent researcher commentary or social media discussion specific to CVE-2026-77110 has been observed, consistent with the absence of public PoC code and active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."