Junglewise Threat Intelligence

CVE-2026-21293: Adobe Commerce Server-Side Request Forgery

CVE-2026-21293 · Severity: medium · CVSS 5.5 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a platform used by online retailers to power e-commerce storefronts, contains a security vulnerability that allows high-privileged attackers to make unauthorized server-side requests and bypass security controls. An attacker exploiting this flaw could access resources they should not be able to reach, potentially compromising the integrity of the commerce platform and the data it protects. No user interaction is required for exploitation.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in affected Adobe Commerce versions that permits security feature bypass. The vulnerability allows a high-privileged attacker to manipulate server-side requests to access unauthorized resources without requiring user interaction. SSRF flaws typically arise from insufficient validation of URLs or network destinations that the server processes on behalf of an attacker. Successful exploitation could allow an attacker to interact with internal services, access restricted resources, or probe internal network topology. Patched versions address input validation and request filtering controls.

Affected products

  • Adobe Commerce 2.4.4-p16 and earlier

Timeline

  • 2026-03-11: disclosed

References

Related threats