Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2024-34102
Adobe Adobe Commerce — XXE can expose crypt key and other secrets granting full admin access
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .9999 100.0 YES
AFFECTED
Product Versions Fixed
Adobe Commerce unspecified —
TIMELINE
Apr 30 Reserved by adobe
Jun 13 Published (CNA: adobe)
Jul 17 Added to CISA KEV, remediation due 2024-08-07
Description
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| April 30, 2024 | Reserved | Reserved by adobe |
| June 13, 2024 | Published | Published (CNA: adobe) |
| July 17, 2024 | KEV ADDED | Added to CISA KEV, remediation due 2024-08-07 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Adobe | Adobe Commerce | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-34102 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.