Adobe Commerce Unrestricted File Upload Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability allowing unrestricted file uploads of dangerous types has been identified in Adobe Commerce. This issue could lead to arbitrary code execution in the context of the current user. An attacker might exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation requires user interaction, as a victim must visit a maliciously crafted URL or engage with a compromised web page.

Impact

Successful exploitation could result in arbitrary code execution, allowing an attacker to execute malicious scripts on the affected system.

Remediation

Users are advised to update to the latest versions of Adobe Commerce. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.

Added: Jul 15, 2026, 5:17 AM
Updated: Jul 15, 2026, 5:17 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
7.5
exploitability
6.8
remediation
7.7
relevance
9.7
threat
0.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.