CVE-2026-75650: Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
Other sources
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
— NVD
Affected Software
Event History
Frequently Asked Questions
Can this be exploited remotely without an account or user interaction?
Yes. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction.
What level of access could successful exploitation provide?
Successful exploitation could allow arbitrary code execution in the context of the current user. The impact is rated high for confidentiality, integrity, and availability, with changed scope.