← Back to browse · API

CVE-2026-48356

Severity
CRITICAL
CVSS
9.3
EPSS
0.28225
Risk score
47.08
CISA KEV
No
PoC
No
Published
2026-07-14
Modified
2026-07-21
First seen
2026-08-05
Aliases
EUVD-2026-44420, GHSA-P3CH-8535-FP8J
Products
Adobe:Adobe Commerce 0 ≤2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18, Adobe:Adobe Commerce B2B 0 ≤1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18, Adobe:Adobe Commerce B2B patch: 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul, Adobe:Adobe Commerce Webhooks Plugin 0 ≤1.20.0, Adobe:Adobe Commerce Webhooks Plugin patch: 1.21.0, Adobe:Adobe Commerce patch: 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul, Magento:Magento Open Source 0 ≤2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, Magento:Magento Open Source patch: 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, adobe:commerce, adobe:commerce_b2b, adobe:i\/o_events, adobe:magento
Sources
nvd CVE-2026-48356
euvd EUVD-2026-44420

Description

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

References