Junglewise Threat Intelligence

CVE-2026-21285: Adobe Commerce incorrect authorization in feature access

CVE-2026-21285 · Severity: medium · CVSS 4.3 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is a widely-used e-commerce platform that manages online stores, payments, and customer data. This vulnerability allows a low-privileged attacker to bypass authorization controls and gain unauthorized access to restricted features without needing to interact with other users. The flaw could enable attackers to perform restricted actions or access sensitive functionality they should not have access to.

Technical details

This is an incorrect authorization vulnerability in Adobe Commerce that allows privilege escalation or feature bypass. A low-privileged attacker can exploit inadequate access controls to gain unauthorized access to protected features without user interaction, indicating the flaw is reachable over the network or through an authenticated session. The vulnerability affects multiple versions of Commerce including 2.4.9-alpha3 down through 2.4.4-p16 and earlier. Adobe has released patches for affected versions; users should upgrade to the latest patched releases.

Affected products

  • Adobe Commerce 2.4.4-p16 and earlier through 2.4.9-alpha3

Timeline

  • 2026-03-11: disclosed

References

Related threats