CVE-2026-34653: Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary file system read and write. An authenticated attacker with administrative privileges could exploit this vulnerability to read or write files outside the restricted directory. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34653?
CVE-2026-34653 is categorized as a high-severity vulnerability due to its potential impact on data security.
How do I fix CVE-2026-34653?
The best fix for CVE-2026-34653 is to upgrade Adobe Commerce to version 2.4.9 or later to mitigate the path traversal risk.
What versions of Adobe Commerce are affected by CVE-2026-34653?
CVE-2026-34653 affects Adobe Commerce versions up to and including 2.4.9-beta1 and earlier.
What type of vulnerability is CVE-2026-34653?
CVE-2026-34653 is classified as an improper limitation of a pathname to a restricted directory, known as a path traversal vulnerability.
Can CVE-2026-34653 lead to data exposure?
Yes, CVE-2026-34653 can lead to unauthorized file access and potential data exposure if exploited.