Junglewise Threat Intelligence

CVE-2026-34654: Adobe Commerce denial of service via vulnerable dependency

CVE-2026-34654 · Severity: medium · CVSS 5.3 · Published 2026-05-12

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used for online storefronts, is affected by a security flaw in one of its third-party components. An attacker can exploit this weakness to crash the website, making it unavailable to customers and disrupting business operations. This attack can be carried out remotely without any interaction from a legitimate user.

Technical details

Adobe Commerce is vulnerable to an application-level denial-of-service (DoS) condition. The root cause is a 'Dependency on Vulnerable Third-Party Component' (CWE-1395) within the application's stack. A remote, unauthenticated attacker can trigger this vulnerability over the network to crash the application. No user interaction or specific privileges are required for successful exploitation. While the specific third-party library is not named in the advisory, the impact is limited to availability (A:L), with no reported impact on data confidentiality or integrity. Users are advised to update to the latest patched versions provided by Adobe.

Affected products

  • Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed: Initial advisory publication by Adobe and NVD.

References

Related threats