A newly disclosed vulnerability dubbed 'PolyShell' affects all Magento Open Source and Adobe Commerce stable version 2 installations, allowing unauthenticated code execution and account takeover. There are no signs of the issue being actively exploited in the wild, but eCommerce security company Sansec warns that "the exploit method is circulating already" and expects automated attacks to start soon. Adobe has released a fix, but it is only available in the second alpha release for version 2.4.9, leaving production versions vulnerable. Sansec says that Adobe offers a "sample web server configuration that would largely limit the fallout," but most stores rely on a setup from their hosting provider. In a report this week, Sansec says that the security problem is rooted in Magento's REST API accepting file uploads as part of the custom options for the cart item. "When a product option has type 'file', Magento processes an embedded file_info object containing base64-encoded file data, a MIME type, and a filename. The file is written to pub/media/custom_options/quote/ on the server," the researchers explain. Sansec says “PolyShell” is named after its use of a polyglot file that can behave as both an image and a script. Depending on the web server configuration, the flaw can enable remote code execution (RCE) or account takeover via stored XSS, impacting most of the stores Sansec analyzed. “Sansec investigated all known Magento and Adobe Commerce stores and found that many stores...
New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores
BleepingComputer
·Bill Toulas
·Published Mar 19, 2026
·Updated
Affected Software
2 affected components
Adobe Magento Open Source>=2.0<3.0
Adobe Commerce>=2.0<3.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a vulnerability known as 'PolyShell' that affects Magento e-stores, allowing unauthenticated remote code execution.
2
What security implications are discussed?
The PolyShell flaw allows unauthorized users to execute code remotely, potentially leading to account takeover.
3
What products or software are affected by the PolyShell vulnerability?
The vulnerability impacts all installations of Magento Open Source and Adobe Commerce stable version 2.
4
Is there evidence of active exploitation of the PolyShell flaw?
As of now, there are no indications that the PolyShell vulnerability is being actively exploited.
5
What versions of Magento are susceptible to the PolyShell flaw?
The affected versions include all Magento Open Source and Adobe Commerce installations from version 2.0 to 3.0.