Input validation error in magento-lts - CVE-2026-40488
Published: April 20, 2026
magento-lts
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in the product custom option file upload handler when processing uploaded files. A remote attacker can upload a specially crafted file with an alternative executable extension to execute arbitrary code.
Exploitation is possible when uploaded files are stored in a publicly accessible directory and the server configuration permits execution of uploaded script files in that location.