Junglewise Threat Intelligence

CVE-2026-21286: Adobe Commerce incorrect authorization in security feature

CVE-2026-21286 · Severity: medium · CVSS 5.3 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an enterprise e-commerce platform used to power online stores and manage product catalogs, inventory, and customer transactions. A flaw in access controls allows attackers to bypass security measures and view sensitive data without proper authorization, without requiring any user interaction. This could expose confidential product information, customer data, or administrative details depending on what data the attacker targets.

Technical details

This is an incorrect authorization vulnerability (CWE-863) in Adobe Commerce that allows authenticated or unauthenticated attackers to bypass security feature controls and gain unauthorized read access to restricted data. The vulnerability affects Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier. The attack vector is network-based and does not require user interaction. The flaw results in a "security feature bypass" allowing limited unauthorized data exposure; exploitation does not grant write access or administrative control. Patches are available for affected versions.

Affected products

  • Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier

Timeline

  • 2026-03-11: disclosed

References

Related threats