Path Traversal Vulnerability in Adobe Commerce
CVE-2026-77110
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-77110?
Adobe Commerce is susceptible to a path traversal vulnerability that permits attackers to bypass security features, enabling them to access unauthorized files and directories beyond the intended limitations. With elevated privileges, an attacker can exploit this weakness to access sensitive data, potentially leading to disruptions in system availability. This vulnerability does not necessitate user interaction for exploitation, making it a significant concern for users of Adobe Commerce.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug