Executive brief
Adobe Commerce is an e-commerce platform used by retailers to manage online storefronts and customer data. A vulnerability in its authorization checks allows attackers to view restricted data and bypass security controls without needing to interact with users or have special permissions, potentially exposing sensitive customer information and business data.
Technical details
This is an Incorrect Authorization vulnerability (CWE-285) in Adobe Commerce that allows attackers to bypass security features and gain unauthorized read access to data. The vulnerability affects versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier. The flaw is network-reachable and requires no user interaction or prior authentication to exploit. An attacker can leverage this to view restricted information they would not normally have access to. Adobe has published security guidance (APSB26-05), though the detailed advisory was not accessible at the time of this report.
Affected products
- Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier
Timeline
- 2026-03-11: disclosed