PT-2026-24566 · Adobe · Commerce
Michele
+1
·
Published
2026-03-10
·
Updated
2026-03-11
·
CVE-2026-21360
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce versions 2.4.4-p16 through 2.4.9-alpha3
Description
The software contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') condition. This could allow a high-privileged attacker to bypass security features and access unauthorized files or directories outside the intended restricted path. Exploitation of this issue does not require user interaction.
Recommendations
Adobe Commerce versions prior to 2.4.4-p16 should be updated.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce