Magento stores vulnerable to remote code execution via ‘PolyShell’ bug, no login needed.
Mar 20, 2026 // 11:17 - Niko Dunn


A newly discovered security flaw, called ‘PolyShell,’ impacts all stable versions of Magento Open Source and Adobe Commerce version 2. It allows unauthorized users to execute code and gain control of accounts.

While there’s no current evidence of active exploitation, the eCommerce security firm Sansec cautions that “the method of exploiting this vulnerability is already being shared” and anticipates that automated attacks will begin soon.

Adobe has provided a fix, but it’s only included in the second alpha release for version 2.4.9, leaving live production versions vulnerable. Sansec notes that Adobe suggests “a sample web server configuration that would significantly reduce the impact,” but most stores rely on hosting provider setups.

According to a report by Sansec this week, the security problem stems from Magento’s REST API accepting file uploads within the custom options for items in the shopping cart.

“If a product option is a ‘file’ type, Magento handles an embedded file_info object containing file data encoded in base64, a MIME type, and a file name. The file is then saved to pub/media/custom_options/quote/ on the server,” the researchers explain.

Sansec says that “PolyShell” gets its name from its ability to use a polyglot file that functions as both an image and a script.

Depending on how the web server is configured, this flaw can lead to remote code execution (RCE) or account takeover through stored XSS, impacting a large number of the stores Sansec analyzed.

“Sansec examined all recognized Magento and Adobe Commerce stores and discovered that many expose files within the upload directory.”

Until Adobe releases the patch for production versions, store administrators are advised to take the following precautions:

  • Restrict access to pub/media/custom_options/
  • Confirm that nginx or Apache rules effectively prevent access there
  • Scan stores to find any uploaded shells, backdoors, or other malicious software

BleepingComputer has reached out to Adobe to inquire about the release timeframe for a PolyShell security update, but has not yet received a response as of this publication.

#‘polyshell’  #bug  #code  #execution  #login,  #magento  #needed  #news  #remote  #stores  #via  #vulnerable   —   News