Junglewise Threat Intelligence

CVE-2026-34646: Adobe Commerce incorrect authorization security bypass

CVE-2026-34646 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Adobe Commerce, Adobe Magento Open Source. Vendors: Adobe.

Executive brief

Adobe Commerce, a leading e-commerce platform used for managing online stores, is affected by a security flaw that allows unauthorized individuals to bypass protection measures. An attacker could exploit this to gain unauthorized write access to the system, potentially allowing them to modify store data or configurations. This attack can be carried out over the internet without any interaction from legitimate users or staff.

Technical details

Adobe Commerce is vulnerable to an Incorrect Authorization (CWE-863) flaw. The vulnerability exists due to improper validation of authorization logic, which allows a remote, unauthenticated attacker to bypass security features. By exploiting this flaw, an attacker can gain unauthorized write access to the application. The attack vector is network-based with low complexity and requires no prior privileges or user interaction. Affected versions include 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier.

Affected products

  • Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
  • Adobe Magento Open Source 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed: Initial publication of the vulnerability advisory.

References

Related threats