Executive brief
Adobe Commerce, a popular e-commerce platform, is affected by a security flaw that could allow an attacker to bypass internal security protections. By tricking a user into clicking a malicious link, an attacker can force the server to perform unauthorized actions, potentially leading to the exposure of sensitive internal data. This could compromise business operations and lead to the theft of confidential information.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in multiple versions of Adobe Commerce. The flaw allows a remote attacker to bypass security measures and gain unauthorized read access to internal resources. Exploitation requires user interaction, specifically requiring a victim to visit a maliciously crafted URL or interact with a compromised web page. The vulnerability is characterized by a 'Changed' scope in the CVSS metric, indicating the attacker can impact components beyond the immediate security scope of the software. Adobe has released security updates to address this issue in the affected versions.
Affected products
- Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory