Junglewise Threat Intelligence

CVE-2026-47984: Adobe Commerce incorrect authorization security bypass

CVE-2026-47984 · Severity: high · CVSS 8.2 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source, Adobe Commerce B2b, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security flaw that allows unauthorized access to sensitive data. An attacker can bypass security checks to read or modify information without needing any user interaction or login credentials. This could lead to the exposure of customer data or unauthorized changes to store configurations and orders.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and related components. The flaw allows a remote, unauthenticated attacker to bypass security features via the network. Successful exploitation grants unauthorized read and write access to the application's data. The vulnerability does not require user interaction and has a high impact on confidentiality. Patches have been released in the July 2026 security updates (e.g., Adobe Commerce 2.4.9-2026-jul and Webhooks Plugin 1.21.0).

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats