Junglewise Threat Intelligence

CVE-2026-34645: Adobe Commerce incorrect authorization security bypass

CVE-2026-34645 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source. Vendors: Adobe.

Executive brief

Adobe Commerce, a leading e-commerce platform used for managing online storefronts, is affected by a security flaw that allows unauthorized individuals to bypass protection measures. An attacker could exploit this to gain unauthorized write access to the system, potentially altering website content or configuration. This vulnerability can be exploited remotely without any interaction from a legitimate user.

Technical details

This vulnerability is classified as Incorrect Authorization (CWE-863) within Adobe Commerce and Magento Open Source. The flaw allows a remote, unauthenticated attacker to bypass security feature checks due to improper validation of authorization logic. Successful exploitation grants the attacker unauthorized write access to the application. The attack vector is network-based with low complexity, requiring no special privileges or user interaction. Adobe has released security updates to address this issue in the affected versions.

Affected products

  • Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
  • Adobe Magento Open Source 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats