CosmicSting
CVE-2024-34102 APSB24-40 Adobe Commerce / Magento 2.x CISA KEV 2024-07-17
If it is 2.4.7 or earlier without the isolated CVE-2024-34102 patch, an unauthenticated XXE chains to remote code execution and encryption-key theft. Verify the exact patch level.
Is my store affected?
A free passive scan tells you whether your store is on an affected line, along with everything else we can see from outside. It takes under a minute and needs no account.
How we detect this
We infer the platform and version line from signals the storefront serves publicly — the version endpoint when it is reachable, markup and cookie markers when it is not, and the fingerprints of static assets that changed between releases. If that line is one CVE-2024-34102 affects, we say so.
We do not attempt to exploit it, and we never claim a store is vulnerable from a version string alone. A patched store and an unpatched one on the same release look identical from outside, so the finding is marked inferred and phrased as something to verify. It does not affect your grade.
How to fix it
Apply Adobe's isolated CVE-2024-34102 patch, rebuild, then rotate the encryption key. The fix is the patch; a full upgrade is optional on top of it.
-
1
See which patches the Quality Patches Tool offers for your exact version.
vendor/bin/magento-patches status
-
2
Apply the standalone isolated patch from Adobe (APSB24-40 / the VULN-27015 hotfix) — it closes this without a version upgrade.
vendor/bin/magento-patches apply VULN-27015 # or: patch -p1 < VULN-27015_2.4.x.patch
-
3
Rebuild so the patched code is compiled and served. This publishes the change; it does not apply it.
bin/magento setup:upgrade && bin/magento setup:di:compile && bin/magento setup:static-content:deploy -f && bin/magento cache:flush
-
4
Rotate the encryption key. CosmicSting leaks it, and patching afterwards does not un-leak a key that was already taken — an attacker holding it can forge admin API tokens against a fully patched store. Back up first: stored data is re-encrypted.
bin/magento encryption:key:change
-
5
Revoke and reissue every integration access token, then re-check any third party you shared credentials with.
-
6
Optional, and separate from the fix: move to a patched release on your line. Use your edition's metapackage and the exact fixed version from the advisory.
composer require magento/product-<your-edition>-edition:<fixed-version> --no-update && composer update
vendor/bin/magento-patches status | grep -i -e VULN-27015 -e 34102
References
We have a longer write-up on this one: CosmicSting (CVE-2024-34102): XXE to encryption-key theft to RCE.
From intelligence vault 2026.09.6, released 2026-09-25. What changed