By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Computing

Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover

News Room
Last updated: 2026/03/20 at 9:34 AM
News Room Published 20 March 2026
Share
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
SHARE

Ravie LakshmananMar 20, 2026Web Security / Vulnerability

Sansec is warning of a critical security flaw in Magento’s REST API that could allow unauthenticated attackers to upload arbitrary executables and achieve code execution and account takeover.

The vulnerability has been codenamed PolyShell by Sansec owing to the fact that the attack hinges on disguising malicious code as an image. There is no evidence that the shortcoming has been exploited in the wild. The unrestricted file upload flaw affects all Magento Open Source and Adobe Commerce versions up to 2.4.9-alpha2.

The Dutch security firm said the problem stems from the fact that Magento’s REST API accepts file uploads as part of the custom options for the cart item.

“When a product option has type ‘file,’ Magento processes an embedded file_info object containing base64-encoded file data, a MIME type, and a filename,” it said. “The file is written to pub/media/custom_options/quote/ on the server.”

Depending on the web server configuration, the flaw can enable remote code execution via PHP upload or account takeover via stored XSS.

Sansec also noted that Adobe fixed the issue in the 2.4.9 pre-release branch as part of APSB25-94, but leaves current production versions without an isolated patch.

“While Adobe provides a sample web server configuration that would largely limit the fallout, the majority of stores use a custom configuration from their hosting provider,” it added.

To mitigate any potential risk, e-commerce storefronts are advised to perform the following steps –

  • Restrict access to the upload directory (“pub/media/custom_options/”).
  • Verify that nginx or Apache rules prevent access to the directory.
  • Scan the stores for web shells, backdoors, and other malware.

“Blocking access does not block uploads, so people will still be able to upload malicious code if you aren’t using a specialized WAF [Web Application Firewall],” Sansec said.

The development comes as Netcraft flagged an ongoing campaign involving the compromise and defacement of thousands of Magento e-commerce sites across multiple sectors and geographies. The activity, which commenced on February 27, 2026, involves the threat actor uploading plaintext files to publicly accessible web directories.

“Attackers have deployed defacement txt files across approximately 15,000 hostnames spanning 7,500 domains, including infrastructure associated with prominent global brands, e-commerce platforms, and government services,” security researcher Gina Chow said.

It’s currently not clear if the attacks are exploiting a specific Magento vulnerability or misconfiguration, and it’s the work of a single threat actor. The campaign has impacted infrastructure belonging to several globally recognized brands, including Asus, FedEx, Fiat, Lindt, Toyota, and Yamaha, among others.

The Hacker News has also reached out to Netcraft to understand if this activity has a connection to PolyShell, and we will update the story if we hear back.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article BTS fans, Spotify has a quiz for you BTS fans, Spotify has a quiz for you
Next Article Access GPT, Claude, Gemini, and More With One AI Tool for Only Access GPT, Claude, Gemini, and More With One AI Tool for Only $85
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Tesla loses its head of Giga Shanghai to a Chinee energy firm · TechNode
Tesla loses its head of Giga Shanghai to a Chinee energy firm · TechNode
Computing
UK Cyber Monitoring Centre plans expansion in US amid risk of Category 5 attack | Computer Weekly
UK Cyber Monitoring Centre plans expansion in US amid risk of Category 5 attack | Computer Weekly
News
Vivo’s best camera phone option has a launch date
Vivo’s best camera phone option has a launch date
Gadget
Platform Engineering as a Practice of Sociotechnical Excellence
Platform Engineering as a Practice of Sociotechnical Excellence
News

You Might also Like

Tesla loses its head of Giga Shanghai to a Chinee energy firm · TechNode
Computing

Tesla loses its head of Giga Shanghai to a Chinee energy firm · TechNode

1 Min Read
Influencer Marketing In-House vs Agency: Which is Better?
Computing

Influencer Marketing In-House vs Agency: Which is Better?

4 Min Read
ODS Layer Design Principles for Modern Data Warehouses | HackerNoon
Computing

ODS Layer Design Principles for Modern Data Warehouses | HackerNoon

18 Min Read
Tech Moves: Carbon Robotics’ new CFO; Microsoft gaming GM goes to Netflix; Nordstrom gets VP of AI
Computing

Tech Moves: Carbon Robotics’ new CFO; Microsoft gaming GM goes to Netflix; Nordstrom gets VP of AI

5 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?