CVE-2026-77110
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-77110 is a Path Traversal vulnerability (CWE-22) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an attacker with high privileges to bypass security restrictions and access unauthorized files or directories outside intended boundaries. The vulnerability was published on September 8, 2026, with a patch made available on September 9, 2026. Affected products include Adobe Commerce versions 2.4.4 through 2.4.9 (and all patch releases within those lines), Adobe Commerce B2B versions 1.3.3 through 1.5.3, and Magento Open Source versions 2.4.6 through 2.4.9. It carries a CVSS v3.1 base score of 7.6 (High) with changed scope (Adobe Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and arises from insufficient validation of file path inputs within Adobe Commerce's administrative functionality. An attacker with high privileges can craft requests that traverse directory boundaries using path manipulation techniques (e.g., ../ sequences or URL-encoded variants), bypassing the application's intended file system restrictions. Exploitation requires no user interaction and is conducted over the network, with the changed scope indicating that the impact extends beyond the vulnerable component itself. Attack patterns associated with this vulnerability include CAPEC-126 (Path Traversal), CAPEC-64 (Using Slashes and URL Encoding to Bypass Validation), and CAPEC-76 (Manipulating Web Input to File System Calls) (Feedly).

Impact

Successful exploitation allows a high-privileged attacker to read or modify files and directories outside the intended restricted paths within the Adobe Commerce installation, resulting in a security feature bypass with high integrity impact and low availability impact. Confidentiality impact is rated as none per the CVSS scoring, though unauthorized file access could expose sensitive configuration data depending on the files reached. The changed scope indicates that resources beyond the vulnerable component — such as the underlying server file system — may be affected, potentially enabling further compromise of the hosting environment (Adobe Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00775 (~0.78%), indicating a low probability of exploitation in the near term. Exploitation requires high privileges (administrative access), which significantly limits the attacker pool.

Exploitation steps

  1. Reconnaissance: Identify Adobe Commerce or Magento Open Source instances running vulnerable versions (2.4.4–2.4.9 for Commerce; 2.4.6–2.4.9 for Magento Open Source) using web fingerprinting tools or version disclosure endpoints.
  2. Obtain High-Privileged Access: Acquire administrative credentials through phishing, credential stuffing, or by leveraging a separate vulnerability — since exploitation requires high privileges.
  3. Craft Path Traversal Payload: Construct a request to an administrative endpoint that accepts file path parameters, embedding traversal sequences such as ../../, URL-encoded variants (%2e%2e%2f), or double-encoded forms to bypass input validation.
  4. Submit Malicious Request: Send the crafted request via the Adobe Commerce admin panel or API to a vulnerable file-handling function, causing the application to resolve a path outside the intended restricted directory.
  5. Access or Modify Unauthorized Files: Retrieve sensitive files (e.g., configuration files, credentials) or overwrite files outside the web root, potentially enabling persistence or further privilege escalation (Feedly, Adobe Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests from administrative accounts to file-handling endpoints containing path traversal sequences (../, %2e%2e, %252e%252e) in parameters; unexpected outbound connections from the Commerce server following admin activity.
  • Logs: Adobe Commerce access logs showing admin-authenticated requests with encoded or raw directory traversal strings in URL parameters or POST bodies; error log entries referencing file access outside the Magento root directory.
  • File System: Unexpected modification timestamps on files outside the web root or Magento installation directory; new or altered configuration files (e.g., env.php, config.php) not corresponding to legitimate admin changes.
  • Process: Unusual file read/write operations by the web server process (e.g., apache, nginx, php-fpm) accessing directories outside the application root.

Mitigation and workarounds

Adobe has released security patches addressing this vulnerability as part of the September 2026 security update (APSB26-138). Administrators should update to the September 2026 patch releases for their respective product lines: Adobe Commerce 2.4.4-2026-sep, 2.4.5-2026-sep, 2.4.6-2026-sep, 2.4.7-2026-sep, 2.4.8-2026-sep, or 2.4.9-2026-sep; Adobe Commerce B2B 1.3.3-2026-sep, 1.3.4-2026-sep, 1.4.2-2026-sep, 1.5.2-2026-sep, or 1.5.3-2026-sep; and Magento Open Source equivalent September 2026 releases. As interim mitigations, restrict administrative access to only authorized personnel, enforce strong authentication (MFA) on admin accounts, and monitor file system access patterns from administrative sessions (Adobe Advisory, Feedly).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution and security bypasses, referencing the September 2026 Adobe patch batch (CIS Advisory). AusCERT published bulletin ESB-2026.10690 covering the Adobe September 2026 releases. No significant independent researcher commentary or social media discussion specific to CVE-2026-77110 has been observed, consistent with the absence of public PoC code and active exploitation.

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77111HIGH8.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77774HIGH8.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77109HIGH8.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77110HIGH7.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77108HIGH7.5
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management