Magento PolyShell: Unauth. Uploads & RCE Lead to Account Takeover (Security Flaw)
Mar 20, 2026 // 14:43 - Norina Velotta


Sansec is alerting users to a serious security vulnerability in Magento’s REST API. This flaw could allow unauthorized individuals to upload harmful files, potentially leading to code execution and control over accounts.

Sansec has named the vulnerability PolyShell because the attack involves concealing malicious code within what appears to be an image. There is no indication this vulnerability has been used in real-world attacks. The unrestricted file upload vulnerability impacts all Magento Open Source and Adobe Commerce versions up to 2.4.9-alpha2.

The Dutch security company explained that the problem arises because Magento’s REST API accepts file uploads as part of the custom options for items in a shopping cart.

“When a product option is a ‘file’ type, Magento handles an embedded file_info object, which contains base64-encoded file data, a MIME type, and a filename,” it stated. “The file gets saved to pub/media/custom_options/quote/ on the server.”

Depending on how the web server is set up, this flaw could lead to remote code execution through PHP upload or account takeover using stored XSS.

Sansec highlighted that Adobe addressed the vulnerability in the 2.4.9 pre-release version as part of APSB25-94, but the current live versions do not have a separate patch.

“Even though Adobe suggests a web server configuration to minimize the impact, most stores use a customized configuration from their hosting provider,” it added.

To reduce potential risks, e-commerce sites are advised to take the following actions:

  • Restrict access to the upload directory (“pub/media/custom_options/”).
  • Ensure that nginx or Apache rules prevent access to the directory.
  • Scan the stores for web shells, backdoors, and other malicious software.

“Blocking access does not prevent uploads. People can still upload malicious code if you are not using a dedicated WAF [Web Application Firewall],” Sansec warned.

#‘polyshell’  #account  #flaw  #lead  #magento  #news  #rce  #security  #takeover  #unauth.  #uploads   —   News