• PoC PUBLIC

CVE-2026-48356: pre-auth remote code execution in Adobe Adobe Commerce

Remote attackers can cause code to execute on Adobe Commerce platforms by making a user upload a crafted file or visit a malicious link. CVE-2026-48356 enables an attacker to bypass upload restrictions and place dangerous content that can run with the privileges of the user interacting with the site. Affected releases include Adobe Commerce 2.x (2.4.9 and earlier listed), Adobe Commerce B2B 1.x (1.5.3 and earlier listed), Magento Open Source 2.x (2.4.9 and earlier listed), and Adobe Commerce Events 1.x (1.20.0 and earlier); exploitation requires a victim to access attacker-controlled content or a specially crafted URL.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.3CRITICAL
EPSS
0.01001
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists for this web-exposed upload flaw that leads to code execution when a user interacts with malicious content—prioritize containment and protective controls now.

What is CVE-2026-48356?

Remote attackers can cause code to execute on Adobe Commerce platforms by making a user upload a crafted file or visit a malicious link. CVE-2026-48356 enables an attacker to bypass upload restrictions and place dangerous content that can run with the privileges of the user interacting with the site. Affected releases include Adobe Commerce 2.x (2.4.9 and earlier listed), Adobe Commerce B2B 1.x (1.5.3 and earlier listed), Magento Open Source 2.x (2.4.9 and earlier listed), and Adobe Commerce Events 1.x (1.20.0 and earlier); exploitation requires a victim to access attacker-controlled content or a specially crafted URL. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Which versions of Adobe Adobe Commerce are affected?

BRANCHAFFECTEDFIXED
Adobe Commerce 2.x2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier
Adobe Commerce B2B 1.x1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18 and earlier
Magento Open Source 2.x2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15 and earlier
Adobe Commerce Events 1.x1.20.0 and earlier

Is CVE-2026-48356 being exploited?

Public exploit code is available.

How to fix CVE-2026-48356

  1. Restrict external access to Adobe Commerce instances and administrative interfaces until mitigations are applied.
  2. Block or validate uploads at the server level and enforce strict content-type and filename checks.
  3. Monitor application and webserver logs for abnormal uploads, unexpected file types, and indicators of webshells or remote file inclusion.
  4. Follow Adobe's official guidance and apply vendor-supplied patches or mitigations as soon as they are released.

Frequently asked questions

Is CVE-2026-48356 being actively exploited?

Public exploit code is available for CVE-2026-48356, which increases the likelihood of active exploitation against Adobe Commerce installations.

Which Adobe Commerce versions are affected by CVE-2026-48356?

Affected releases include Adobe Commerce 2.x (2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 and earlier), Adobe Commerce B2B 1.x (1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18 and earlier), Magento Open Source 2.x (2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15 and earlier), and Adobe Commerce Events 1.x (1.20.0 and earlier).

Is there a patch for CVE-2026-48356?

No fixed versions are listed in the provided facts; apply mitigations and monitor Adobe advisories for official patches.

What can an attacker do with CVE-2026-48356?

By inducing a victim to interact with attacker-controlled content, an adversary can upload a malicious file and execute code under the victim's web application privileges on vulnerable Adobe Commerce systems.

References