Junglewise Threat Intelligence

CVE-2026-34648: Adobe Commerce uncontrolled resource consumption in application core

CVE-2026-34648 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used for online storefronts, is vulnerable to a flaw that allows attackers to crash the website. By sending specific requests, an attacker can exhaust the server's resources, making the store unavailable to legitimate customers. This could lead to lost sales and reputational damage during the period of the outage.

Technical details

Adobe Commerce versions up to 2.4.9-beta1 are vulnerable to uncontrolled resource consumption (CWE-400). The vulnerability exists in the application's handling of incoming requests, where an attacker can trigger excessive resource allocation. This is a network-based attack that requires no authentication (PR:N) and no user interaction (UI:N). Successful exploitation allows a remote attacker to exhaust CPU or memory resources, resulting in a complete denial-of-service for the application. Users are advised to update to the latest patched versions provided by Adobe.

Affected products

  • Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats