Magento Remote Code Execution (StyleSmuggler)

critical Web App Scanning Plugin ID 115470

Synopsis

Magento Remote Code Execution (StyleSmuggler)

Description

Magento Open Source / Adobe Commerce is affected by an unauthenticated remote code execution vulnerability known as StyleSmuggler. A remote attacker is able to write PHP code in the application log file through the unescaped store code reported by the GraphQL endpoint, then store a set of nested email directives in the billing address of a guest cart. The global string substitutions performed when the address is rendered wrap the attacker directive with a valid deferred signature, which smuggles an administration preview block into the failed payment email template. That block replays the 'type', 'text' and 'styles' parameters of the current HTTP request, allowing the attacker to instantiate an arbitrary class before its type is validated and to reach a dependency injection scanner which includes the poisoned log file. The whole chain is triggered by a public GraphQL mutation and requires no account, no cart item and no payment method, allowing an attacker to execute arbitrary code in the context of the web server process.

Note that this plugin requires the 'File Upload' assessment option enabled in the scan configuration.

Solution

Apply the appropriate patch according to the vendor advisory. As a temporary measure, apply one of the available community mitigations, restrict access to the GraphQL endpoint or filter the requests containing nested 'styles' parameters and email directives in address fields.

See Also

https://github.com/magento/magento2/pull/41231

https://helpx.adobe.com/security/products/magento/apsb26-146.html

Plugin Details

Severity: Critical

ID: 115470

Type: Check Based

Published: 9/8/2026

Updated: 9/8/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 8

Percentile: 99.68

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-75650

CVSS v3

Risk Factor: Critical

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS Score Source: CVE-2026-75650

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 9/4/2026

Reference Information

CVE: CVE-2026-75650