Adobe Commerce and Magento Open Source Path Traversal Vulnerability Allowing Arbitrary File System Access

Vulnerability

A path traversal vulnerability has been identified in Adobe Commerce and Magento Open Source versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier. This vulnerability allows authenticated attackers with administrative privileges to read or write files outside of restricted directories, potentially leading to unauthorized file system access. The issue can be exploited without user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized reading or writing of files on the server, potentially leading to further exploitation or data exposure.

Remediation

Users are advised to update to Adobe Commerce versions 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 or to Magento Open Source versions 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15.

Added: May 12, 2026, 9:00 PM
Updated: May 12, 2026, 9:00 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.0
exploitability
5.0
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.