Executive brief
Adobe Commerce, a popular e-commerce platform used for managing online stores, is affected by a security flaw that allows attackers to bypass certain security protections. By tricking a user into clicking a malicious link or visiting a compromised website, an attacker could gain unauthorized ability to modify data on the platform. This could potentially lead to unauthorized changes to store settings or customer-facing content.
Technical details
An improper authorization vulnerability (CWE-285) exists in Adobe Commerce versions up to 2.4.9-beta1 and various patched branches. The flaw allows a remote attacker to bypass security features and achieve unauthorized write access. Exploitation requires network connectivity and user interaction, specifically requiring a victim to visit a maliciously crafted URL or interact with a compromised web page. The vulnerability is rated medium severity with a CVSS score of 4.3, primarily impacting integrity without affecting confidentiality or availability. Users are advised to update to the latest patched versions provided by Adobe.
Affected products
- Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory