Junglewise Threat Intelligence

CVE-2026-21309: Adobe Commerce incorrect authorization security feature bypass

CVE-2026-21309 · Severity: high · CVSS 7.5 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an e-commerce platform used to power online stores and manage product sales. A flaw in the authorization controls allows attackers to bypass security features and gain unauthorized access to sensitive data without any user interaction required. This could expose customer information, order details, or other confidential business data stored in the system.

Technical details

The vulnerability is an Incorrect Authorization flaw in Adobe Commerce that allows attackers to circumvent security controls and gain unauthorized view access to protected data. The issue affects versions 2.4.4-p16 and earlier through 2.4.9-alpha3, and exploitation does not require user interaction, indicating it is remotely accessible. An attacker can leverage this to bypass security measures and access sensitive information, potentially compromising customer data or internal operations. Adobe has documented this in security bulletin APSB26-05, though the detailed technical advisory is not currently accessible.

Affected products

  • Adobe Commerce 2.4.4-p16 and earlier through 2.4.9-alpha3

Timeline

  • 2026-03-11: disclosed: Vulnerability publicly disclosed
  • 2026-03-11: advisory: Adobe APSB26-05 advisory published

References

Related threats