Executive brief
Adobe Commerce, a popular e-commerce platform used for online storefronts, is affected by a security flaw that allows attackers to crash the website. By sending specific requests that consume excessive server resources, an attacker can make the store unavailable to legitimate customers. This could lead to lost sales and reputational damage during the period of the outage.
Technical details
Adobe Commerce is vulnerable to uncontrolled resource consumption (CWE-400). The flaw allows a remote, unauthenticated attacker to trigger excessive resource usage on the hosting server via the network. Successful exploitation results in a denial-of-service (DoS) condition, impacting the availability of the application. No user interaction is required for exploitation. The vulnerability is addressed in the APSB26-49 security update.
Affected products
- Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
- Adobe Magento 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Adobe security bulletin APSB26-49 published