CVE-2026-77110
largePath Traversal Security Bypass in Adobe Commerce and Magento
CVE-2026-77110 is a path traversal flaw (CWE-22) in Adobe Commerce that allows an attacker to reach files or directories outside the intended restricted directory boundaries, resulting in a security feature bypass. It is triggered over the network by an already-authenticated attacker with high privileges (such as an admin-level account) and requires no user interaction. Per Adobe's CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L), exploitation has a high impact on integrity via bypassing security restrictions, a low impact on availability, and the 'changed scope' rating indicates the attack crosses into other security zones of the application. It affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source deployments running the affected versions (version ranges were not specified in the source data). As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.8% probability of exploitation within 30 days (54th percentile).
What to do: Check the Adobe PSIRT security bulletin for CVE-2026-77110 to identify the affected version ranges and upgrade Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to the patched release. Until patched, restrict admin accounts to least privilege, enforce MFA on admin logins, and review access logs for unexpected admin activity or unusual file access. No public exploit exists, so there is no need to hunt for a specific PoC signature, but prioritize patching given the high integrity impact.
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| Adobe Magento (Open Source) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.