CVE-2024-34102: critical vulnerability in Adobe Commerce
XXE can expose crypt key and other secrets granting full admin access
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe Commerce has a flaw that allows attackers to send specially crafted XML files to expose sensitive secrets like encryption keys and gain complete admin access to the store. This happens automatically without needing any user interaction.
An XXE (XML External Entity) vulnerability in affected Adobe Commerce versions (2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier) permits unauthenticated remote attackers to read arbitrary files and extract cryptographic keys through crafted XML payloads submitted to vulnerable endpoints. Successful exploitation grants administrative privileges and potential code execution without requiring user action or authentication.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.