Improper Encoding or Escaping of Output in Adobe products - CVE-2026-48358
Published: July 15, 2026
Vulnerability identifier: #VU137586
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-48358
CWE-ID: CWE-116
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper encoding or escaping of output in webhooks when processing webhook data. A remote privileged user can trigger the flaw to execute arbitrary code.
Only webhooks are affected.
Affected software
Adobe Commerce B2B
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
How to mitigate CVE-2026-48358
Install security update from vendor's website.
Adobe Commerce B2B - addressed in versions 1.3.3-2026-jul, 1.3.4-2026-jul, 1.4.2-2026-jul, 1.5.2-2026-jul, 1.5.3-2026-jul
Magento Open Source - addressed in versions 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul
Magento Open Source - addressed in versions 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4-2026-jul, 2.4.5-2026-jul, 2.4.6-2026-jul, 2.4.7-2026-jul, 2.4.8-2026-jul, 2.4.9-2026-jul