Adobe Commerce B2B Arbitrary Code Execution (APSB26-146)

critical Nessus Plugin ID 344800

Synopsis

The Adobe Commerce B2B module installed on the remote host is missing a security hotfix.

Description

The version of the Adobe Commerce B2B module installed on the remote host is affected by a vulnerability as referenced in the APSB26-146 advisory.

- Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. (CVE-2026-75650)

Adobe resolved this issue with the VULN-39341 hotfix, which patches the underlying Adobe Commerce core rather than the B2B module and does not change any reported version. Because the hotfix state cannot be confirmed from the B2B module version alone, this plugin reports the module as potentially affected. The authoritative fix status for the host is reported by the Adobe Commerce / Magento Open Source check.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Apply the VULN-39341 hotfix as referenced in the vendor advisory, then rotate the encryption key and every credential that may have been encrypted or exposed with it.

See Also

https://helpx.adobe.com/security/products/magento/apsb26-146.html

https://sansec.io/research/stylesmuggler-0day

http://www.nessus.org/u?78a58ae4

Plugin Details

Severity: Critical

ID: 344800

File Name: adobe_commerce_b2b_apsb26-146.nasl

Version: 1.1

Type: Local

Agent: unix

Family: Misc.

Published: 9/11/2026

Updated: 9/11/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-75650

CVSS v3

Risk Factor: Critical

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:adobe:commerce_b2b

Required KB Items: Settings/ParanoidReport, installed_sw/Adobe Commerce B2B

Patch Publication Date: 9/7/2026

Vulnerability Publication Date: 9/5/2026

Reference Information

CVE: CVE-2026-75650