Junglewise Threat Intelligence

CVE-2026-34649: Adobe Commerce uncontrolled resource consumption leading to DoS

CVE-2026-34649 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a leading e-commerce platform, is affected by a security flaw that allows attackers to crash the website or make it unresponsive. By sending specific requests that consume excessive system resources, an attacker can prevent legitimate customers from accessing the store or completing purchases. This could lead to significant revenue loss and operational disruption during the period of the outage.

Technical details

Adobe Commerce versions up to 2.4.9-beta1 are vulnerable to uncontrolled resource consumption (CWE-400). The vulnerability allows a remote, unauthenticated attacker to send requests that exhaust server-side resources such as CPU, memory, or disk space. This results in an application-level denial-of-service (DoS), making the platform unavailable to users. The attack vector is network-based with low complexity and requires no special privileges or user interaction. Administrators should update to the latest patched versions provided by Adobe to mitigate this risk.

Affected products

  • Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats