Unauthenticated file upload in Amasty Order Attributes for Magento
by Sansec Forensics Team
Published in Threat Research − June 12, 2026
An unauthenticated arbitrary file upload flaw in Amasty Order Attributes (CVE-2026-53787) lets attackers write executable files to a Magento store without logging in, opening the door to remote code execution. Amasty fixed it in version 4.0.0. Sansec Shield has already blocked over 12,000 attacks against more than 100 stores.

Amasty Order Attributes contains an unauthenticated arbitrary file upload vulnerability. An attacker can upload a file of any type and name to the store's media directory with no login, no session and no cart. Where that directory can execute PHP, this leads to remote code execution (CWE-434).
All versions up to and including 3.16.0 are affected. Amasty released a fix, version 4.0.0, on June 12, 2026. The vulnerability is tracked as CVE-2026-53787 and has a critical CVSS score of 9.3.
Sansec Shield blocks these uploads in real time, so stores running Shield have been protected.
A quietly patched flaw
Amasty's changelog describes the 4.0.0 release as "we enhanced code to resolve a potential security vulnerability." The same notes flag the change as backward incompatible, because a new mandatory attribute_code parameter was added to the upload endpoint. The fix validates uploads before committing them, enforces an extension allow-list and requires a real file attribute.
Impact for merchants
A successful upload effectively hands full control of the server to the attacker:
- Remote code execution: Where
pub/mediacan execute PHP, an uploaded script runs with the web server's privileges: payment skimmers, backdoors, admin account creation and data theft. - Malware hosting: Stores that block PHP execution can still be turned into hosts for
.pharpayloads, phishing kits and other malware served from a trusted domain. - Stored XSS and SVG injection: Uploaded HTML or SVG files execute scripts in a visitor's or administrator's browser, leading to session theft and admin takeover.
- Path traversal: On 3.16.0 the unsanitized filename also lets an attacker write outside the intended
amasty_checkoutfolder. On versions prior to 2.4.2 it escapes the media directory entirely.
The attack needs no credentials, fires on ordinary storefront traffic and is trivial to automate across many stores. Now that a patch exists, the fix points attackers at the vulnerable code, so unpatched stores face rising scanning pressure.
Exploited in the wild
Attacks started the same day the patch shipped. Sansec Shield blocked the first exploitation attempt on June 12, 2026, hours after Amasty published version 4.0.0. Mass scanning followed on June 14.
By June 15, Shield had blocked more than 12,000 exploitation attempts against 25% of all Magento stores, from 45 distinct IP addresses. The campaign is ongoing.
The attacks hit the REST upload endpoint and its store and locale variants:
POST /rest/V1/amasty_orderattr/uploadFile
POST /rest/all/V1/amasty_orderattr/uploadFile
POST /rest/default/V1/amasty_orderattr/uploadFile
A typical request uploads a file named index.php with a fingerprint payload:
{
"fileContent": {
"base64_encoded_data": "PD9waHAgZWNobyAnR09PRCc7IGVjaG8gMyozOTU7ID8+",
"fileName_with_extension": "index.php"
}
}
The base64 blob decodes to a code-execution probe:
<?php echo 'GOOD'; echo 3*395; ?>
The ten most active attacker IP addresses:
87.237.202.229
88.167.123.203
23.234.102.171
50.7.159.158
94.177.131.77
146.70.165.145
185.88.213.248
31.125.27.61
38.175.103.98
213.123.206.176
Sansec Shield protection
Sansec Shield inspects incoming requests at your application servers and blocks attempts to upload executable or dangerous file types to these endpoints. The file is rejected before it reaches disk, regardless of how pub/media is configured.
This protection is not tied to a version or signature. Shield evaluates the upload itself, so it stops abuse of this flaw and the wider class of unauthenticated upload attacks against Magento extensions. Stores that cannot patch right away stay protected.
Recommendations
- Update now: Upgrade Amasty Order Attributes to 4.0.0 or later. The release is backward incompatible: the upload API now requires an
attribute_codeparameter. - Block attacks: Deploy Sansec Shield to block these uploads in real time, including on stores that cannot patch immediately.
- Scan for compromise: Run eComscan to detect webshells, backdoors and other malware.
- Check web directories: Review unexpected files, especially
.php,.phtml,.phar,.htmland.svg. - Block PHP in media: Ensure
pub/mediacannot execute PHP as defense in depth.
Timeline
| Date | Event |
|---|---|
| June 12, 2026 | Amasty releases fixed version 4.0.0 |
| June 12, 2026 | Sansec Shield rules deployed |
| June 12, 2026 | This advisory published |
| June 12, 2026 | CVE-2026-53787 published |
| June 12, 2026 | Shield blocks first live attack |
| June 14, 2026 | Mass scanning observed |
Read more
In this article
Protect your store now!
Block all known Magento attacks, while you schedule the latest critical patch until a convenient moment. No more downtime and instability from rushed patching.
Get Sansec ShieldScan your store now
for malware & vulnerabilities
eComscan is the most thorough security scanner for Magento, Adobe Commerce, Shopware, WooCommerce, Sylius and many more.
Learn more