Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-75650Template Injection RCE in Adobe Commerce

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

View on NVD

Analysis

Adobe Commerce permite la ejecución remota de código (RCE) debido a una neutralización inadecuada en su motor de plantillas. Un atacante puede ejecutar comandos arbitrarios sin necesidad de interacción por parte del usuario, comprometiendo la integridad total del servidor de e-commerce. Esta vulnerabilidad cuenta con la calificación máxima de severidad CVSS 10.0.

Relevant roles

PhpBackendciberseguridad

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-1336

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Published: 9/7/2026, 9:17:30 PM
Last modified: 9/7/2026, 9:17:30 PM

References

HomeEventsBlogResourcesCoursesTeam