Executive brief
Adobe Commerce is an e-commerce platform used to power online stores and manage product sales. A flaw in the authorization controls allows attackers to bypass security features and gain unauthorized access to sensitive data without any user interaction required. This could expose customer information, order details, or other confidential business data stored in the system.
Technical details
The vulnerability is an Incorrect Authorization flaw in Adobe Commerce that allows attackers to circumvent security controls and gain unauthorized view access to protected data. The issue affects versions 2.4.4-p16 and earlier through 2.4.9-alpha3, and exploitation does not require user interaction, indicating it is remotely accessible. An attacker can leverage this to bypass security measures and access sensitive information, potentially compromising customer data or internal operations. Adobe has documented this in security bulletin APSB26-05, though the detailed technical advisory is not currently accessible.
Affected products
- Adobe Commerce 2.4.4-p16 and earlier through 2.4.9-alpha3
Timeline
- 2026-03-11: disclosed: Vulnerability publicly disclosed
- 2026-03-11: advisory: Adobe APSB26-05 advisory published