CVE-2024-20758: Adobe Commerce

Critical severity, CVSS 9.0. EPSS: 1.4% chance of exploitation in the next 30 days.

Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on the underlying filesystem. Exploitation of this issue does not require user interaction, but the attack complexity is high.

Affected products

  • Adobe Commerce: affected versions not specified; version 2.3.7 only; version 2.4.0 only; version 2.4.1 only; version 2.4.2 only; version 2.4.3 only; …
  • Adobe Magento: version 2.4.4 only; version 2.4.5 only; version 2.4.6 only; version 2.4.7 only

Published 2024-04-10. Last modified 2026-06-17.