CVE-2026-40488 affects OpenMage LTS versions prior to 20.17.0, a community-maintained e-commerce platform. The vulnerability exists in the custom option file upload functionality, which uses an incomplete blocklist (php, exe) that can be easily bypassed using alternative PHP-executable extensions such as phtml, phar, php3-php7, and pht. When combined with inadequate server-side execution restrictions in the publicly accessible media/custom_options/quote/ directory, this flaw enables unauthenticated remote code execution on affected systems. The attack vector is network-based and appears to have low complexity, requiring only the ability to upload a file with an alternative PHP extension and access to a web server without explicit script execution denial in the media directory. The potential impact is severe, allowing attackers to execute arbitrary code with web server privileges and potentially gain full system compromise. The vulnerability is currently on the active Hot List but has not yet appeared in CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting no confirmed active exploitation in the wild at this time. However, the straightforward nature of the bypass technique and the relatively high FAUCET Risk Score of 51.0/100 indicate significant community attention and risk potential. Organizations running OpenMage LTS should upgrade to version 20.17.0 or implement directory-level execution restrictions as a mitigation measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.17.0CPE matchmatch criteria | cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.