CVE-2022-24086

CRITICAL(9.8)KEVLikely Exploited

Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability

Description

CVE-2022-24086 is a CRITICAL improper input validation vulnerability affecting Adobe Commerce and Magento Open Source, carrying a CVSS 3.1 score of 9.8. Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. Affected products include Adobe Commerce (< 2.3.0; >= 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3), Adobe Magento (< 2.3.0; > 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3). This CVE is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of 2022-03-01. With an EPSS score of 0.93483 (99.82th percentile), this vulnerability demonstrates significant real-world exploitation activity and should be prioritized for immediate remediation.

KEV Information

Vendor
Adobe
Product
Commerce and Magento Open Source
Date Added
February 15, 2022
Due Date
March 1, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
adobecommerce< 2.3.0; >= 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3
adobemagento< 2.3.0; > 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3

References

Weakness Type

CWE-20: Improper Input Validation

CVE-2022-24086 is classified under CWE-20 — Improper Input Validation. Improper Input Validation is a software weakness where a product receives input or data but does not validate or incorrectly validates that the input has the properties required to process data safely and correctly. This vulnerability occurs when applications accept user-supplied data without verifying that it conforms to expected formats, lengths, types, or ranges. Attackers can exploit this weakness by providing malicious, malformed, or unexpected input to alter program behavior, gain unauthorized access, execute arbitrary code, or cause denial of service. Input validation failures are the root cause of many critical vulnerabilities including SQL injection, cross-site scripting (XSS), command injection, buffer overflows, and path traversal attacks.

In the context of Adobe Commerce and Magento Open Source, this weakness is particularly concerning because Applications that fail to properly validate input expose themselves to a wide range of attacks that can compromise confidentiality, integrity, and availability. Attackers can craft malicious inputs to bypass security controls, execute unauthorized commands, access sensitive data, or crash systems. The impact varies from information disclosure to complete system compromise, often leading to significant financial losses, regulatory penalties, and reputational damage. Organizations using affected versions should understand that this vulnerability class has historically enabled severe compromises across enterprise environments.

Impact Analysis

CVE-2022-24086 carries a CVSS 3.1 score of 9.8 (CRITICAL) with Unchanged Scope.

Confidentiality (HIGH): Successful exploitation grants the attacker extensive access to sensitive data processed by Adobe Commerce and Magento Open Source, including configuration files, credentials, and potentially data from connected systems.

Integrity (HIGH): Attackers can modify critical system files, install backdoors, alter configurations, or deploy malware on affected systems running Adobe Commerce and Magento Open Source.

Availability (HIGH): Complete disruption of the affected service or system is possible, including denial of service, system crashes, or rendering the product inoperable.

Scope Unchanged: The vulnerability's scope is Unchanged (U), meaning exploitation is contained within the vulnerable component. The impact, while significant, is limited to the Adobe Commerce and Magento Open Source environment itself.

With an EPSS score of 0.93483 (99.82th percentile), this vulnerability ranks among the most likely to be exploited in real-world attacks, underscoring the urgency of remediation.

Exploit Maturity

CVE-2022-24086 has confirmed active exploitation in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog.

Exploit status: This vulnerability has been actively exploited, as confirmed by its inclusion in the KEV catalog. The EPSS score of 0.93483 (99.82th percentile) places it among the most exploited vulnerabilities tracked.

Ransomware association: As of the latest KEV data, no direct ransomware association has been confirmed for CVE-2022-24086. However, the confirmed exploitation in the wild means threat actors are actively using this vulnerability in attacks.

Attack surface: While specific public exploit code may not be readily available, the vulnerability's high EPSS score and KEV listing confirm that threat actors have developed and used working exploits. Organizations should assume exploitation tools exist in underground markets and private threat actor toolkits.

KEV deadline: CISA required federal agencies to remediate this vulnerability by 2022-03-01. All organizations should treat this deadline as a strong recommendation for their own remediation timelines.

Remediation

  1. Apply vendor patches immediately. Apply updates per vendor instructions. Consult the vendor advisory at helpx.adobe.com for specific patch guidance.
  2. Verify affected product versions in your environment. Identify all instances of Adobe Commerce and Magento Open Source in your infrastructure (affected versions: Adobe Commerce (< 2.3.0; >= 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3), Adobe Magento (< 2.3.0; > 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3)). Use asset inventory and vulnerability scanning tools to ensure no instances are missed.
  3. Implement interim mitigations if patching is delayed. If immediate patching is not feasible, apply network-level controls such as restricting access to the affected component, enabling enhanced logging, and monitoring for indicators of compromise.
  4. Scan for signs of prior exploitation. Given the confirmed active exploitation of this vulnerability, review system logs and security monitoring data for evidence of compromise. Conduct a thorough investigation if any suspicious activity is detected.
  5. Update detection signatures and monitoring rules. Ensure intrusion detection and prevention systems, endpoint detection tools, and SIEM rules are updated to detect exploitation attempts targeting CVE-2022-24086.
  6. Conduct a post-remediation review. After patching, verify the fix is effective and document the remediation actions taken. Update your vulnerability management records and assess whether any additional hardening measures are warranted.

Technical Details

CVE-2022-24086 is a CRITICAL-severity vulnerability in Adobe Commerce and Magento Open Source that can be exploited remotely over the network without physical access. The attack complexity is low, meaning no specialized conditions or preparation are required beyond the attack prerequisites. No prior authentication or privileges are needed to initiate the attack. No user interaction is required, allowing fully automated exploitation once the target is accessible.

Technical mechanism: Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. The underlying flaw relates to improper input validation, where Improper Input Validation is a software weakness where a product receives input or data but does not validate or incorrectly validates that the input has the properties required to process data safely and correctly. This vulnerability occurs when applications accept user-supplied data without verifying that it conforms to expected formats, lengths, types, or ranges.

CVSS 3.1 vector analysis: The vector reflects an Attack Vector of NETWORK, Attack Complexity of LOW, Privileges Required of NONE, User Interaction of NONE, Scope UNCHANGED, and impact ratings of HIGH/HIGH/HIGH for Confidentiality/Integrity/Availability respectively. The Unchanged scope means impact is contained within the vulnerable component itself.

Frequently Asked Questions

What is CVE-2022-24086?

CVE-2022-24086 is a CRITICAL-severity vulnerability (CVSS 9.8) in Adobe Commerce and Magento Open Source that adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution. It is listed in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation.

Which products are affected by CVE-2022-24086?

The affected products include Adobe Commerce (< 2.3.0; >= 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3), Adobe Magento (< 2.3.0; > 2.3.3, <= 2.3.6; >= 2.4.0, <= 2.4.2; 2.3.7; 2.4.3). Organizations running any of these versions should verify their exposure and prioritize remediation. Check vendor advisories for the complete and most current list of affected versions.

How do I fix CVE-2022-24086?

Apply updates per vendor instructions. Ensure all affected instances of Adobe Commerce and Magento Open Source are identified using vulnerability scanning and asset management tools. If immediate patching is not possible, implement network-level mitigations and enhanced monitoring. After patching, verify the fix and scan for indicators of prior compromise.

How severe is CVE-2022-24086?

CVE-2022-24086 is rated CRITICAL with a CVSS 3.1 score of 9.8. Its EPSS score of 0.93483 places it in the 99.82th percentile for exploitation likelihood. The vulnerability has confirmed active exploitation in the wild and was required to be remediated by federal agencies by 2022-03-01 per CISA's KEV directive.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score99.11%
EPSS Percentile99.9%

Dates

PublishedFebruary 16, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.