CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-48356

Critical · CVSS 9.3

Adobe Commerce (Magento) — Unrestricted File Upload leading to Arbitrary Code Execution (CWE-434)

CVSS
9.3
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-434

Description

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

Search profile — drives PoC discovery

Symbols file uploaddangerous file typearbitrary code executionmalicious script injectionelevated accesssession hijackingchanged scope
Keywords CVE-2026-48356Adobe CommerceMagentounrestricted file uploadCWE-434APSB26-73arbitrary code executionfile upload bypassPoCexploit
Versions: Adobe Commerce versions affected per APSB26-73

References

Status: enriched · ingested 2026-07-15T18:00:20.000Z · profiled 2026-07-15T18:30:20.000Z