CVE-2026-77110
Dashboard / Vulnerabilities / CVE-2026-77110
CVE-2026-77110
Summary: Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Details: Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77110.json, https://helpx.adobe.com/security/products/magento/apsb26-138.html, https://nvd.nist.gov/vuln/detail/CVE-2026-77110
Affected packages
Package
Name:
Purl:
