A deserialization vulnerability in Adobe Commerce and Adobe Magento allows an attacker to send specially crafted requests that can bypass authentication. This flaw can be combined with file-upload functionality to achieve remote code execution (RCE).
Impact
An unauthenticated attacker can compromise the system.
Remediation
Upgrade to the latest version of Adobe Commerce/Magento