Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Langflow critical flaw CVE-2026-33017 triggers attacks within 20 hours of publication

Cyberattack on car breathalyzer company leaves drivers stranded across the US

Live Science Today: The Monte Verde controversy and the heatwave that hits the West

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Magento PolyShell flaw allows unauthorized uploads, RCEs, and account takeover
Identity

Magento PolyShell flaw allows unauthorized uploads, RCEs, and account takeover

By March 20, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 20, 2026Web security/vulnerabilities

Sansec warns that Magento’s REST API has a critical security flaw that could allow an unauthenticated attacker to upload arbitrary executable files and perform code execution or account takeover.

This vulnerability was codenamed PolyShell by Sansec due to the fact that the attack relies on disguising malicious code as an image. There is no evidence that this shortcoming has been exploited in practice. The unlimited file upload flaw affects all Magento open source and Adobe Commerce versions up to 2.4.9-alpha2.

The Dutch security firm said the issue stems from the fact that Magento’s REST API accepts file uploads as part of the custom options for cart items.

“If the product option is of type ‘file’, Magento processes an embedded file_info object containing the base64-encoded file data, MIME type, and file name.” “The file will be written to pub/media/custom_options/quote/ on the server.”

Depending on the web server configuration, this vulnerability could allow remote code execution via PHP upload or account takeover via stored XSS.

Sansec also noted that Adobe fixed the issue in the 2.4.9 pre-release branch as part of APSB25-94, but no separate patch has been applied to the current product version.

“Adobe provides sample web server configurations that greatly reduce the impact, but most stores use custom configurations from their hosting providers,” it added.

To reduce potential risks, we recommend that e-commerce stores take the following steps:

Restrict access to the upload directory (‘pub/media/custom_options/’). Verify that nginx or Apache rules are preventing access to the directory. Scan your store for web shells, backdoors, and other malware.

“Blocking access does not block uploads, so malicious code can be uploaded even if you are not using a specialized WAF. [Web Application Firewall]” said Sansek.

This development comes after Netcraft alerted us to an ongoing campaign involving the compromise and defacement of thousands of Magento e-commerce sites across multiple sectors and geographies. This activity, which began on February 27, 2026, involves threat actors uploading cleartext files to publicly accessible web directories.

“The attackers deployed defaced txt files to approximately 15,000 hostnames across 7,500 domains, including infrastructure related to well-known global brands, e-commerce platforms, and government services,” said security researcher Gina Chow.

It is currently unclear whether the attack exploits specific Magento vulnerabilities or misconfigurations, and is the work of a single attacker. This campaign impacted the infrastructure of world-renowned brands such as Asus, FedEx, Fiat, Lindt, Toyota, and Yamaha.

Hacker News also reached out to Netcraft to understand if this activity is connected to PolyShell. I will update the article if I receive a response.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUK National Cryogenic Facility Advances Quantum Technology
Next Article Using plasma technology to break down PFAS contaminants

Related Posts

Langflow critical flaw CVE-2026-33017 triggers attacks within 20 hours of publication

March 20, 2026

Google adds 24-hour wait for sideloading unverified apps to reduce malware and fraud

March 20, 2026

The importance of behavioral analysis in cyber attacks using AI

March 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Langflow critical flaw CVE-2026-33017 triggers attacks within 20 hours of publication

Cyberattack on car breathalyzer company leaves drivers stranded across the US

Live Science Today: The Monte Verde controversy and the heatwave that hits the West

The best investment in AI may be in energy technology

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.