High severity7.6NVD Advisory· Published Sep 8, 2026· Updated Sep 8, 2026
CVE-2026-77110
CVE-2026-77110
Description
Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.