Executive brief
Adobe Commerce is an e-commerce platform used by retailers to manage online storefronts and customer transactions. A flaw in input validation allows attackers to bypass security controls without needing user interaction, potentially affecting the integrity of commerce operations and data protection mechanisms.
Technical details
An improper input validation vulnerability exists in Adobe Commerce versions 2.4.9-alpha3 through 2.4.4-p16 and earlier. The flaw resides in the input validation logic and allows attackers to circumvent security features. The vulnerability is network-accessible and does not require user interaction or authentication. Successful exploitation can result in a security feature bypass with limited impact to data integrity. Patches are available in versions 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, and 2.4.8-p3.
Affected products
- Adobe Commerce 2.4.4-p16 and earlier including 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15
Timeline
- 2026-03-11: disclosed