CVE-2022-24086 is a critical improper input validation vulnerability affecting Adobe Commerce and Magento versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) during the checkout process. This flaw carries a CVSS score of 9.8 (CRITICAL) and allows for arbitrary code execution without user interaction, posing a severe risk to confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in the CISA KEV catalog, and has garnered significant community discussion and media coverage, despite no public Metasploit or ExploitDB modules. Nuclei templates for detection are available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* | ||
>= 2.3.3, <= 2.3.6CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* | ||
>= 2.4.0, <= 2.4.2CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* | ||
2.3.7CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:* | ||
2.3.7CPE matchmatch criteria | cpe:2.3:a:adobe:commerce:2.3.7:p2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.