ZeroHour

CVE-2026-77110

large

Path Traversal Security Bypass in Adobe Commerce and Magento

CVSS 3.1
7.6 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-77110 is a path traversal flaw (CWE-22) in Adobe Commerce that allows an attacker to reach files or directories outside the intended restricted directory boundaries, resulting in a security feature bypass. It is triggered over the network by an already-authenticated attacker with high privileges (such as an admin-level account) and requires no user interaction. Per Adobe's CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L), exploitation has a high impact on integrity via bypassing security restrictions, a low impact on availability, and the 'changed scope' rating indicates the attack crosses into other security zones of the application. It affects Adobe Commerce, Adobe Commerce B2B, and Magento Open Source deployments running the affected versions (version ranges were not specified in the source data). As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.8% probability of exploitation within 30 days (54th percentile).

What to do: Check the Adobe PSIRT security bulletin for CVE-2026-77110 to identify the affected version ranges and upgrade Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to the patched release. Until patched, restrict admin accounts to least privilege, enforce MFA on admin logins, and review access logs for unexpected admin activity or unusual file access. No public exploit exists, so there is no need to hunt for a specific PoC signature, but prioritize patching given the high integrity impact.

Affected
Adobe Commerce
Adobe Commerce B2B
Adobe Magento (Open Source)
Estimated exposure
largeon the order of 100,000+ stores (public trackers show Magento/Adobe Commerce in the low hundreds of thousands of live shops worldwide) — Market-share trackers and internet-wide scans consistently count Magento/Adobe Commerce in the low hundreds of thousands of live e-commerce stores, and because the flaw only needs an authenticated high-privileged session, all unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:L

In the news

No ingested article mentions this CVE yet.