CVE-2026-48356
Critical · CVSS 9.3Adobe Commerce (Magento) — Unrestricted File Upload leading to Arbitrary Code Execution (CWE-434)
- CVSS
- 9.3
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-434
Description
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Search profile — drives PoC discovery
Symbols file uploaddangerous file typearbitrary code executionmalicious script injectionelevated accesssession hijackingchanged scope
Keywords CVE-2026-48356Adobe CommerceMagentounrestricted file uploadCWE-434APSB26-73arbitrary code executionfile upload bypassPoCexploit
Versions: Adobe Commerce versions affected per APSB26-73
References
Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z