CVE-2024-39401
Status: AnalyzedHigh (8.4)—
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
- Base score: 8.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.67%
- Percentile among all scored CVEs: 76
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-78
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-39401",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-39401",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-14T14:10:32.512995Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.4,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.7
}
]
},
"affected": [
{
"source": "psirt@adobe.com",
"affectedData": [
{
"vendor": "Adobe",
"product": "Adobe Commerce",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "2.4.4-p9"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*"
],
"vendor": "adobe",
"product": "commerce",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.4.7-p1"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.4.6-p6"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.4.5-p8"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.4.4-p9"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-08-14T12:15:25.097",
"references": [
{
"url": "https://helpx.adobe.com/security/products/magento/apsb24-61.html",
"tags": [
"Vendor Advisory"
],
"source": "psirt@adobe.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@adobe.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an admin attacker. Exploitation of this issue requires user interaction and scope is changed."
},
{
"lang": "es",
"value": " Las versiones 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 y anteriores de Adobe Commerce se ven afectadas por una neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando del sistema operativo ('inyección de comando del sistema operativo') eso podría provocar la ejecución de código arbitrario por parte de un atacante administrador. La explotación de este problema requiere la interacción del usuario y se cambia el alcance."
}
],
"lastModified": "2026-06-17T07:41:52.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCD55BE5-59AF-4C75-9187-A90F23262716",
"versionEndIncluding": "2.4.3"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D258D9EF-94FB-41F0-A7A5-7F66FA7A0055"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E5CF6F0-2388-4D3F-8FE1-43B8AF148564"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6D6F1A7-ABB5-4EDC-9EA8-98B74518847A"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFEBDDF2-6443-4482-83B2-3CD272CF599F"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6661093F-8D22-450F-BC6C-A8894A52E6A9"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2515DA6D-2E74-4A05-BD29-FEEF3322BCB6"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69A1F1F7-E53C-40F3-B3D9-DC011FC353BF"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6A56E96C-6CE5-442C-AA88-F0059B02B5E7"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8867F510-201C-4199-8554-53DE156CE669"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.4:p9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "23988132-DD4E-4968-B6B8-954122F76081"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B07F7B2-E915-4EFF-8FFC-91143CEF082E"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F5E9DB6-1386-4274-8270-2FE0F0CAF7FD"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8605E4E6-0F7D-42C8-B35B-2349A0BEFC69"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6318F97-E59A-4425-8DC7-045C78A644F8"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "324A573E-DBC8-42A0-8CB8-EDD8FBAB7115"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54151A00-CFB8-4E6A-8E74-497CB67BF7E2"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DF0E74D-9293-4209-97D1-A3BA13C3DDE9"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8922D646-1A97-47ED-91C6-5A426781C98A"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.5:p8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "952787C6-9BF1-49FB-9824-1236678E1902"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C7AFBB1-F9C9-4BDE-BCEF-94C9F0AC6798"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6086841-C175-46A1-8414-71C6163A0E7A"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2E0DDD1-0F4A-4F96-B25D-40A39A1A535A"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A576B1B5-73A2-431E-998F-7E5458B51D6A"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E05F4AC-2A28-47E3-96DE-0E31AF73CD43"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A9A62EE-1649-4815-8EC9-7AEF7949EB2F"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.6:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E58690F9-FA9C-42A0-B4CD-91FD1197A53E"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.7:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5D04853-0C2F-47DD-A939-3A8F6E22CB7D"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.7:b1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6EBB0608-034B-4F07-A59B-9E6A989BA260"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.7:b2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B3BF9B08-84E3-4974-9DEB-F4285995D796"
},
{
"criteria": "cpe:2.3:a:adobe:commerce:2.4.7:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E05341A-C70C-4B3D-AF30-9520D6B97D30"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11A61231-5593-481E-A28C-A68BC6EEC49A",
"versionEndIncluding": "2.4.3"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC641EFE-3B9B-4988-A143-FE1F6FD0D689"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p1:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F7AA4A6-69E3-4BA4-A476-CA37F41D5482"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p2:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3D05570-FA72-4FCF-90E9-EC19731CD9F7"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p3:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7DF079F1-1886-4974-A0F0-82DEA88F2E83"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p4:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4E7AFE2-E02D-4C7D-B9C3-CEF345F1287C"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p5:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F39BCCFC-4748-4626-8E35-4BD299CE42A5"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p6:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB9003A6-F5CC-463F-AC3A-C76F96A39F45"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p7:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10DBD0CA-AFC2-4E12-9239-C2FBE778E6E4"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p8:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBB3AA19-BF6C-4C4B-A213-494D35F08D99"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.4:p9:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FE43B88-BCD6-4ADF-94E7-81EC15550A67"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A41C717-4B9F-4972-ABA3-2294EEC20F3E"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p1:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FA80BBC-2DF2-46E1-84CE-8A899415114E"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p2:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "510B1840-AE77-4BDD-9C09-26C64CC8FC81"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p3:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA1EDF58-8384-48C4-A584-54D24F6F7973"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p4:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D2D9715-3A6B-4BE0-B1C5-8D19A683A083"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p5:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C99B578-5DD6-476D-BB75-4DCAD7F79535"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p6:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C1B2897-79A5-4A5B-9137-7A4B6B85AA84"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p7:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9E8299D-FA97-483A-8E1B-BA7B869E467D"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.5:p8:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A1B92EC-E83A-43B3-8F14-5C1A52B579B1"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "789BD987-9DAD-4EAE-93DE-0E267D54F124"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:p1:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A3F113C0-00C5-4BC2-B42B-8AE3756252F2"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:p2:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02592D65-2D2C-460A-A970-8A18F9B156ED"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:p3:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "457B89CF-C75E-4ED6-8603-9C52BA462A9E"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:p4:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A572A2DC-2DAB-4ABE-8FC2-5AF2340C826F"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:p5:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A2DD9C6-BAF5-4DF5-9C14-3478923B2019"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.6:p6:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BA9CFC70-24CF-4DFA-AEF9-9B5A9DAF837D"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.7:-:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E06FE04-8844-4409-92D9-4972B47C921B"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.7:b1:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99C620F3-40ED-4D7F-B6A1-205E948FD6F5"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.7:b2:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBCFE5FB-FAB7-4BF0-90AE-79F9590FD872"
},
{
"criteria": "cpe:2.3:a:adobe:magento:2.4.7:p1:*:*:open_source:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C77154A-DBFE-48C3-A274-03075A0DB040"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@adobe.com"
}