← Vulnerability feed

Vulnerability record · CVE-2024-34102 · published 13 June 2024

CVE-2024-34102: Adobe Commerce and Magento XXE flaw allows unauthenticated code execution

Adobe · Commerce

Adobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML document referencing external entities can be processed by the application, and the vendor states this can result in arbitrary code execution. The flaw is remotely reachable without authentication or user interaction, making it a serious risk for exposed storefronts.

9.8 CVSS 3.1 Critical CISA KEV since 17 Jul 2024 EPSS 100% · top 0.1% CWE-611 · XML external entity (XXE)
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network exploitation, CISA KEV listing and near-maximum EPSS probability make this an urgent patch-first issue.

What it is

Adobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML document referencing external entities can be processed by the application, and the vendor states this can result in arbitrary code execution. The flaw is remotely reachable without authentication or user interaction, making it a serious risk for exposed storefronts.

Impact

An unauthenticated attacker can send a crafted XML document to trigger XXE and, per the advisory, achieve arbitrary code execution on the affected Commerce or Magento instance. That gives full control over the application and its data, with high confidentiality, integrity and availability impact.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges (PR:N) and no user interaction (UI:N), so it can be triggered directly by sending a crafted XML request to the affected service. No authentication is required.

Exploitation

CVE-2024-34102 is listed in CISA KEV with a due date of 2024-08-07, and EPSS shows a 30-day probability of 0.99994 (99.988th percentile). Public exploit and technical description references exist, so active exploitation should be assumed.

What to do

  • Apply the Adobe Commerce/Magento security update referenced in Adobe advisory APSB24-40 for your release line (2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier).
  • If immediate patching is not possible, follow Adobe's documented mitigations or take the instance offline, as directed by CISA KEV guidance.
  • Restrict network access to Commerce/Magento admin and API endpoints to trusted sources and place the application behind a WAF or reverse proxy that blocks XML external entity payloads.
  • Disable or harden XML parsing where possible, rejecting DOCTYPE declarations and external entity references in incoming XML.
  • Review logs and configuration for signs of prior exploitation before and after patching, since the flaw may have been used before remediation.

Detection

  • Search web and application logs for XML requests containing DOCTYPE or ENTITY declarations, especially referencing external or file URIs.
  • Monitor for unexpected outbound connections from the Commerce/Magento host to attacker-controlled or unusual destinations, which can indicate XXE data exfiltration.
  • Look for anomalous child processes or file writes originating from the web server/PHP process that could indicate post-exploitation code execution.
  • Correlate requests to known vulnerable endpoints with KEV/EPSS-driven alerting and review for repeated crafted XML submissions from single sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-34102 to the Known Exploited Vulnerabilities catalog on 17 July 2024 as "Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 August 2024.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-34102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-75650Adobe Commerce template engine flaw allows unauthenticated remote code executionAdobe Commerce, Commerce B2B and Magento are affected by improper neutralization of special elements used in a template engine (CWE-1336), allowing a…KEVEPSS 3.9%analysed9.8CVE-2022-24086Adobe Commerce and Magento improper input validation in checkout enables RCEAdobe Commerce (2.4.3-p1 and earlier, 2.3.7-p2 and earlier) and Magento Open Source fail to properly validate input during the checkout process. The …KEVEPSS 99%analysed9.1CVE-2026-71362Adobe commerce incorrect authorization vulnerabilityAdobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…KEVEPSS 88%9.1CVE-2025-54236Adobe Commerce improper input validation enables session takeoverAdobe Commerce and Magento are affected by improper input validation (CWE-20) across multiple 2.4.x branches and earlier. A remote, unauthenticated a…KEVEPSS 95%analysed9.8CVE-2024-45115Adobe commerce improper authentication vulnerabilityAdobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could resul…EPSS 1.3%9.8CVE-2024-34107Adobe commerce improper access control vulnerabilityAdobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in…EPSS 1.1%9.8CVE-2022-34256Adobe commerce improper authorization vulnerabilityAdobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerabilit…EPSS 2.1%9.3CVE-2026-76200Adobe magento cross-site scripting vulnerabilityAdobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into …EPSS 0.74%

Source: NIST National Vulnerability Database (record CVE-2024-34102), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.