Executive brief
Adobe Commerce, a leading e-commerce platform used for managing online stores, is affected by a security flaw that allows attackers to crash the website. By sending specific requests that consume excessive system resources, an attacker can make the storefront unavailable to legitimate customers. This could lead to lost sales, operational downtime, and reputational damage during the period the site is offline.
Technical details
This vulnerability (CWE-400) is classified as Uncontrolled Resource Consumption within Adobe Commerce and Magento Open Source. An unauthenticated remote attacker can exploit this flaw by sending crafted requests that exhaust server-side resources such as CPU, memory, or disk space. The attack does not require any user interaction and can be executed over the network. Successful exploitation results in a Denial-of-Service (DoS) condition, rendering the application unresponsive. Adobe has released security updates to address this issue in the affected versions.
Affected products
- Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
- Adobe Magento Open Source 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory