Executive brief
Adobe Commerce, a leading e-commerce platform used for managing online storefronts, is affected by a security flaw that allows unauthorized individuals to bypass protection measures. An attacker could exploit this to gain unauthorized write access to the system, potentially altering website content or configuration. This vulnerability can be exploited remotely without any interaction from a legitimate user.
Technical details
This vulnerability is classified as Incorrect Authorization (CWE-863) within Adobe Commerce and Magento Open Source. The flaw allows a remote, unauthenticated attacker to bypass security feature checks due to improper validation of authorization logic. Successful exploitation grants the attacker unauthorized write access to the application. The attack vector is network-based with low complexity, requiring no special privileges or user interaction. Adobe has released security updates to address this issue in the affected versions.
Affected products
- Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
- Adobe Magento Open Source 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory