CVE-2026-77110: Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires an attacker to already hold high privileges in Adobe Commerce. It is remotely exploitable, has low attack complexity, and does not require user interaction.
What is the likely impact if exploitation succeeds?
A high-privileged attacker could bypass a security feature and access files or directories outside intended path restrictions. The stated impact includes integrity consequences and limited availability disruption; confidentiality impact is listed as none.
Does this issue affect default or unauthenticated Adobe Commerce deployments?
The available information does not establish whether a default configuration is affected. It does establish that unauthenticated attackers are not the intended threat model, because high privileges are required.