Remote Code Execution Vulnerability in OpenMage LTS e-commerce Platform
CVE-2026-40488
8.7HIGH
What is CVE-2026-40488?
The OpenMage Long Term Support (LTS) e-commerce platform is vulnerable due to an insufficient blocklist for file uploads in custom options. This security flaw allows attackers to upload malicious files with executable extensions such as .phtml and .phar, which can be executed due to improper server configurations. This vulnerability can lead to unauthorized remote code execution if the directory storing these files lacks sufficient access controls. Users are advised to upgrade to version 20.17.0 or later for protection against this security risk.
Affected Version(s)
magento-lts < 20.17.0
