Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security flaw that allows unauthorized access to sensitive data. An attacker can bypass security checks to read or modify information without needing any user interaction or login credentials. This could lead to the exposure of customer data or unauthorized changes to store configurations and orders.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and related components. The flaw allows a remote, unauthenticated attacker to bypass security features via the network. Successful exploitation grants unauthorized read and write access to the application's data. The vulnerability does not require user interaction and has a high impact on confidentiality. Patches have been released in the July 2026 security updates (e.g., Adobe Commerce 2.4.9-2026-jul and Webhooks Plugin 1.21.0).
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory