Evidence dossier

CVE-2024-34102

XXE can expose crypt key and other secrets granting full admin access

Exploited in the wild (CISA KEV since Jul 17, 2024). adobe reports CVSS 3.1 9.8. EPSS estimates 100.0% exploit likelihood as of Jul 31, 2026.

88.694.3Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

State
PUBLISHED
Published
Jun 13, 2024
Updated
Oct 21, 2025
Evidence coverage
97%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    adobe

    Record text: XXE can expose crypt key and other secrets granting full admin access

    Inspect raw assertion
    Field
    container
    Value
    XXE can expose crypt key and other secrets granting full admin access
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.99% probability · 99.99th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999910000000; percentile 0.999860000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Jul 17, 2024 · first observed Jul 19, 2026

Exploit likelihood99.99%

FIRST EPSS · score date Jul 31, 2026 · 100th percentile · first observed Aug 1, 2026

SeverityCVSS 9.8

adobe · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

adobeOriginal assertion
Record text

XXE can expose crypt key and other secrets granting full admin access

Inspect raw assertion
Field
container
Value
XXE can expose crypt key and other secrets granting full admin access
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.99% probability · 99.99th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999910000000; percentile 0.999860000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
59Underlying assertions
3Canonical products
59Target assertions
0Constraint assertions

Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

13 scope groups

CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
CISA-ADP · source assertedadobecommerceDirect source scope
Affected: 0 through 2.4.7 (custom comparison)Affected: 0 through 2.4.6-p5 (custom comparison)Affected: 0 through 2.4.5-p7 (custom comparison)Affected: 0 through 2.4.4-p8 (custom comparison)Affected: 0 through 2.4.3-ext-7 (custom comparison)Affected: 0 through 2.4.2-ext-7 (custom comparison)Affected: 0 through 2.4.1-ext-7 (custom comparison)Affected: 0 through 2.4.0-ext-7 (custom comparison)Affected: 0 through 2.3.7-p4-ext-7 (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.6-p5"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.5-p7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.4-p8"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.3-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.2-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.1-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.4.0-ext-7"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "2.3.7-p4-ext-7"}]
adobe · source assertedAdobeAdobe CommerceDirect source scope
Affected: 0 through 2.4.4-p8 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "0", "versionType": "semver", "lessThanOrEqual": "2.4.4-p8"}]
NVD CPE · APPLICATIONadobecommerceVulnerable target · 33 assertions
Version 2.4.2; Version 2.4.3; Version 2.4.4; Version 2.4.5; Version 2.4.6; Version 2.4.7Canonical identity product-4f9e417403ee5779da342a16f6238abe5aac2ea26bd39a70bbc320fef7d3fb73Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:adobe:commerce:2.4.4:p6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69a1f1f7-e53c-40f3-b3d9-dc011fc353bf
  2. cpe:2.3:a:adobe:commerce:2.4.2:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    62bf6a4c-bc58-40a2-ae21-b4f309562661
  3. cpe:2.3:a:adobe:commerce:2.4.3:ext-1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fc5b997c-8db4-4fdf-96f6-6dcf23970705
  4. cpe:2.3:a:adobe:commerce:2.4.4:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2515da6d-2e74-4a05-bd29-feef3322bcb6
  5. cpe:2.3:a:adobe:commerce:2.4.6:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3a9a62ee-1649-4815-8ec9-7aef7949eb2f
  6. cpe:2.3:a:adobe:commerce:2.4.6:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a576b1b5-73a2-431e-998f-7e5458b51d6a
  7. cpe:2.3:a:adobe:commerce:2.4.6:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d2e0ddd1-0f4a-4f96-b25d-40a39a1a535a
  8. cpe:2.3:a:adobe:commerce:2.4.2:ext-1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1d0e8bc4-17bd-4f42-a849-2cc439cf82d8
  9. cpe:2.3:a:adobe:commerce:2.4.3:ext-2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8b1341e-a0c9-42eb-8bae-e23d88bc3cb0
  10. cpe:2.3:a:adobe:commerce:2.4.5:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    324a573e-dbc8-42a0-8cb8-edd8fbab7115
  11. cpe:2.3:a:adobe:commerce:2.4.5:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7f5e9db6-1386-4274-8270-2fe0f0caf7fd
  12. cpe:2.3:a:adobe:commerce:2.4.5:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8605e4e6-0f7d-42c8-b35b-2349a0befc69
  13. cpe:2.3:a:adobe:commerce:2.4.6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c7afbb1-f9c9-4bde-bcef-94c9f0ac6798
  14. cpe:2.3:a:adobe:commerce:2.4.5:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9b07f7b2-e915-4eff-8ffc-91143cef082e
  15. cpe:2.3:a:adobe:commerce:2.4.4:p4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6661093f-8d22-450f-bc6c-a8894a52e6a9
  16. cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d258d9ef-94fb-41f0-a7a5-7f66fa7a0055
  17. cpe:2.3:a:adobe:commerce:2.4.5:p7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8922d646-1a97-47ed-91c6-5a426781c98a
  18. cpe:2.3:a:adobe:commerce:2.4.7:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5d04853-0c2f-47dd-a939-3a8f6e22cb7d
  19. cpe:2.3:a:adobe:commerce:2.4.5:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b6318f97-e59a-4425-8dc7-045c78a644f8
  20. cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4e5cf6f0-2388-4d3f-8fe1-43b8af148564
  21. cpe:2.3:a:adobe:commerce:2.4.4:p2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6d6f1a7-abb5-4edc-9ea8-98b74518847a
  22. cpe:2.3:a:adobe:commerce:2.4.3:ext-3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    14ceafb8-0812-4f19-8e83-93a61a23594f
  23. cpe:2.3:a:adobe:commerce:2.4.4:p3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cfebddf2-6443-4482-83b2-3cd272cf599f
  24. cpe:2.3:a:adobe:commerce:2.4.3:ext-7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ffcf3470-0c38-4f54-9bff-b5819805aecb
  25. cpe:2.3:a:adobe:commerce:2.4.3:ext-4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    25a9ac2f-7aac-41ff-8d93-3a5cbe24bed6
  26. cpe:2.3:a:adobe:commerce:2.4.2:ext-3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f2b3ef0e-31b4-4508-ac48-d89cb4460d89
  27. cpe:2.3:a:adobe:commerce:2.4.4:p8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8867f510-201c-4199-8554-53de156ce669
  28. cpe:2.3:a:adobe:commerce:2.4.2:ext-4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b0b4abdb-1c22-4b26-ba4d-da73ed1f50d2
  29. cpe:2.3:a:adobe:commerce:2.4.6:p1:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6086841-c175-46a1-8414-71c6163a0e7a
  30. cpe:2.3:a:adobe:commerce:2.4.3:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7b503c35-8c90-4a24-8e60-722cdbbf556b
  31. cpe:2.3:a:adobe:commerce:2.4.2:ext-7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f4f3cdeb-7bee-44f7-a927-dca209429d96
  32. cpe:2.3:a:adobe:commerce:2.4.5:p5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    54151a00-cfb8-4e6a-8e74-497cb67bf7e2
  33. cpe:2.3:a:adobe:commerce:2.4.2:ext-2:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e9e12ec1-36a9-42f5-9ee6-88faa6fd52f3
NVD CPE · APPLICATIONadobecommerce_webhooksVulnerable target · 1 assertions
Any version (unconstrained) (>= 1.2.0, < 1.5.0)Canonical identity product-20e63d09c18d026f17076657d06d95b8097ce4e1d6c074611b23483ddf7af1bcLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:adobe:commerce_webhooks:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 33
    Logic
    OR
    Version bounds
    from including 1.2.0; through excluding 1.5.0
    Match ID
    7ec901f8-73e4-4b13-9855-d7b157d37ea3
NVD CPE · APPLICATIONadobemagentoVulnerable target · 25 assertions
Version 2.4.4; Version 2.4.5; Version 2.4.6; Version 2.4.7Canonical identity product-93b17b2849c0a89f7601c92bffa8c491fbbc634bf8f11b99010d95c779e324dfLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:adobe:magento:2.4.5:p3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fa1edf58-8384-48c4-a584-54d24f6f7973
  2. cpe:2.3:a:adobe:magento:2.4.4:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5f7aa4a6-69e3-4ba4-a476-ca37f41d5482
  3. cpe:2.3:a:adobe:magento:2.4.6:p3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    457b89cf-c75e-4ed6-8603-9c52ba462a9e
  4. cpe:2.3:a:adobe:magento:2.4.6:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    789bd987-9dad-4eae-93de-0e267d54f124
  5. cpe:2.3:a:adobe:magento:2.4.7:b1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    99c620f3-40ed-4d7f-b6a1-205e948fd6f5
  6. cpe:2.3:a:adobe:magento:2.4.4:p3:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7df079f1-1886-4974-a0f0-82dea88f2e83
  7. cpe:2.3:a:adobe:magento:2.4.4:p8:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fbb3aa19-bf6c-4c4b-a213-494d35f08d99
  8. cpe:2.3:a:adobe:magento:2.4.4:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ac641efe-3b9b-4988-a143-fe1f6fd0d689
  9. cpe:2.3:a:adobe:magento:2.4.6:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a3f113c0-00c5-4bc2-b42b-8ae3756252f2
  10. cpe:2.3:a:adobe:magento:2.4.4:p5:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f39bccfc-4748-4626-8e35-4bd299ce42a5
  11. cpe:2.3:a:adobe:magento:2.4.4:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a3d05570-fa72-4fcf-90e9-ec19731cd9f7
  12. cpe:2.3:a:adobe:magento:2.4.6:p5:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2a2dd9c6-baf5-4df5-9c14-3478923b2019
  13. cpe:2.3:a:adobe:magento:2.4.5:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7a41c717-4b9f-4972-aba3-2294eec20f3e
  14. cpe:2.3:a:adobe:magento:2.4.5:p7:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b9e8299d-fa97-483a-8e1b-ba7b869e467d
  15. cpe:2.3:a:adobe:magento:2.4.5:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    510b1840-ae77-4bdd-9c09-26c64cc8fc81
  16. cpe:2.3:a:adobe:magento:2.4.5:p5:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1c99b578-5dd6-476d-bb75-4dcad7f79535
  17. cpe:2.3:a:adobe:magento:2.4.6:p4:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a572a2dc-2dab-4abe-8fc2-5af2340c826f
  18. cpe:2.3:a:adobe:magento:2.4.5:p1:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3fa80bbc-2df2-46e1-84ce-8a899415114e
  19. cpe:2.3:a:adobe:magento:2.4.7:-:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0e06fe04-8844-4409-92d9-4972b47c921b
  20. cpe:2.3:a:adobe:magento:2.4.4:p7:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    10dbd0ca-afc2-4e12-9239-c2fbe778e6e4
  21. cpe:2.3:a:adobe:magento:2.4.4:p6:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    eb9003a6-f5cc-463f-ac3a-c76f96a39f45
  22. cpe:2.3:a:adobe:magento:2.4.4:p4:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c4e7afe2-e02d-4c7d-b9c3-cef345f1287c
  23. cpe:2.3:a:adobe:magento:2.4.6:p2:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02592d65-2d2c-460a-a970-8a18f9b156ed
  24. cpe:2.3:a:adobe:magento:2.4.5:p6:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c1b2897-79a5-4a5b-9137-7a4b6b85aa84
  25. cpe:2.3:a:adobe:magento:2.4.5:p4:*:*:open_source:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d2d9715-3a6b-4be0-b1c5-8d19a683a083

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

9.8
psirt@adobe.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
adobeCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.