CVE-2026-21360: Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restricted path. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21360?
CVE-2026-21360 is classified with a high severity due to the potential for path traversal attacks that can lead to unauthorized access to sensitive files.
How do I fix CVE-2026-21360?
To mitigate CVE-2026-21360, upgrade Adobe Commerce to version 2.4.9-alpha4 or apply any listed patches provided by Adobe.
What types of systems are affected by CVE-2026-21360?
CVE-2026-21360 affects Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, and earlier, making those systems vulnerable to exploitation.
What kind of attack does CVE-2026-21360 enable?
CVE-2026-21360 enables path traversal attacks, allowing attackers to access files that should be restricted.
Is there a workaround for CVE-2026-21360?
No known workaround exists for CVE-2026-21360; the only recommended action is to upgrade to a secure version of Adobe Commerce.