Remote Code Execution Vulnerability in OpenMage LTS e-commerce Platform
CVE-2026-40488

8.7HIGH

Key Information:

Vendor

Openmage

Vendor
CVE Published:
20 April 2026

What is CVE-2026-40488?

The OpenMage Long Term Support (LTS) e-commerce platform is vulnerable due to an insufficient blocklist for file uploads in custom options. This security flaw allows attackers to upload malicious files with executable extensions such as .phtml and .phar, which can be executed due to improper server configurations. This vulnerability can lead to unauthorized remote code execution if the directory storing these files lacks sufficient access controls. Users are advised to upgrade to version 20.17.0 or later for protection against this security risk.

Affected Version(s)

magento-lts < 20.17.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.