Junglewise Threat Intelligence

CVE-2026-21297: Adobe Commerce incorrect authorization in security feature

CVE-2026-21297 · Severity: medium · CVSS 4.3 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an e-commerce platform used by businesses to build and manage online stores. A vulnerability in authorization logic allows low-privileged attackers to bypass security restrictions and gain unauthorized access to protected features without needing to interact with users, potentially exposing sensitive functionality or administrative controls.

Technical details

This is an incorrect authorization vulnerability (CWE-863) in Adobe Commerce that permits a security feature bypass. A low-privileged authenticated attacker can exploit flawed authorization checks in a protected feature to gain access beyond their intended permissions. The vulnerability is network-accessible and does not require user interaction; exploitation requires only valid credentials at a reduced privilege level. Affected versions include 2.4.4-p16 and earlier through 2.4.9-alpha3. Adobe has published remediation details in security bulletin APSB26-05, though the vendor advisory page was not fully accessible at time of analysis.

Affected products

  • Adobe Commerce 2.4.4-p16 and earlier, up to and including 2.4.9-alpha3

Timeline

  • 2026-03-11: disclosed

References

Related threats