CVE-2026-48356: Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48356?
The severity of CVE-2026-48356 is critical with a score of 9.6.
How do I fix CVE-2026-48356?
To fix CVE-2026-48356, ensure that file upload mechanisms restrict the types of files that can be uploaded and sanitize all user inputs.
What impact does CVE-2026-48356 have on Adobe Commerce?
CVE-2026-48356 allows an attacker to upload malicious files, leading to arbitrary code execution within the context of the current user.
Which software versions are affected by CVE-2026-48356?
CVE-2026-48356 affects Adobe Commerce, Adobe Commerce B2B, and Adobe Magento systems.
What type of vulnerability is CVE-2026-48356 classified as?
CVE-2026-48356 is classified as an Unrestricted Upload of File with Dangerous Type vulnerability, categorized under CWE-434.