Executive brief
Adobe Commerce is an e-commerce platform used to build and manage online storefronts. A flaw in authorization logic allows low-privileged users to bypass security controls and view data they should not be able to access. This could expose sensitive customer or business information without requiring the attacker to interact with users.
Technical details
The vulnerability is an incorrect authorization flaw in Adobe Commerce that permits a low-privileged attacker to bypass security feature logic. The affected versions include 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier. An authenticated attacker can exploit this without user interaction to gain unauthorized view access to restricted data. The vulnerability requires an existing user account but allows escalation of privileges beyond normal authorization boundaries.
Affected products
- Adobe Commerce 2.4.4-p16 and earlier through 2.4.9-alpha3
Timeline
- 2026-03-11: disclosed