• News/
  • https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/

New ‘PolyShell’ flaw allows unauthenticated RCE on Magento e-stores

BleepingComputer
·
Bill Toulas
·
Published Mar 19, 2026
·
Updated

A newly disclosed vulnerability dubbed 'PolyShell' affects all Magento Open Source and Adobe Commerce stable version 2 installations, allowing unauthenticated code execution and account takeover. There are no signs of the issue being actively exploited in the wild, but eCommerce security company Sansec warns that "the exploit method is circulating already" and expects automated attacks to start soon. Adobe has released a fix, but it is only available in the second alpha release for version 2.4.9, leaving production versions vulnerable. Sansec says that Adobe offers  a "sample web server configuration that would largely limit the fallout," but most stores rely on a setup from their hosting provider. In a report this week, Sansec says that the security problem is rooted in Magento's REST API accepting file uploads as part of the custom options for the cart item. "When a product option has type 'file', Magento processes an embedded file_info object containing base64-encoded file data, a MIME type, and a filename. The file is written to pub/media/custom_options/quote/ on the server," the researchers explain. Sansec says “PolyShell” is named after its use of a polyglot file that can behave as both an image and a script. Depending on the web server configuration, the flaw can enable remote code execution (RCE) or account takeover via stored XSS, impacting most of the stores Sansec analyzed. “Sansec investigated all known Magento and Adobe Commerce stores and found that many stores...

Read full article

Affected Software

2 affected components
Adobe Magento Open Source>=2.0<3.0
Adobe Commerce>=2.0<3.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability known as 'PolyShell' that affects Magento e-stores, allowing unauthenticated remote code execution.

2

What security implications are discussed?

The PolyShell flaw allows unauthorized users to execute code remotely, potentially leading to account takeover.

3

What products or software are affected by the PolyShell vulnerability?

The vulnerability impacts all installations of Magento Open Source and Adobe Commerce stable version 2.

4

Is there evidence of active exploitation of the PolyShell flaw?

As of now, there are no indications that the PolyShell vulnerability is being actively exploited.

5

What versions of Magento are susceptible to the PolyShell flaw?

The affected versions include all Magento Open Source and Adobe Commerce installations from version 2.0 to 3.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203