Executive brief
Adobe Commerce is an e-commerce platform used to power online stores and manage product catalogs. A flaw in how the application validates user input can allow an attacker to craft malicious requests that crash or disable the platform, interrupting sales and customer access without requiring any special account access or user interaction.
Technical details
The vulnerability is an improper input validation flaw in Adobe Commerce that enables a denial-of-service (DoS) attack. An unauthenticated attacker on the network can send specially crafted input to the application, triggering a crash or resource exhaustion that degrades or disables availability. No user interaction or authentication is required to trigger the issue. The vulnerability affects multiple versions through 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, and 2.4.9-alpha3, with patches available in subsequent versions.
Affected products
- Adobe Commerce 2.4.4-p16 and earlier through 2.4.9-alpha3
Timeline
- 2026-03-11: disclosed: CVE-2026-21282 published on NVD