Junglewise Threat Intelligence

CVE-2026-47988: Adobe Commerce incorrect authorization security bypass

CVE-2026-47988 · Severity: high · CVSS 8.6 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source, Adobe Commerce B2b, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security flaw that allows unauthorized access to sensitive data. An attacker could bypass existing security controls to read or modify information without needing a valid account or any interaction from a legitimate user. This could lead to the theft of customer data or unauthorized changes to the store's operations.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and the Adobe Commerce Webhooks Plugin. The flaw allows a remote, unauthenticated attacker to bypass security features via the network. Successful exploitation grants unauthorized read and write access to the application's data and functionality. The vulnerability does not require user interaction and has a CVSS 3.1 base score of 8.6. Patches have been released in the July 2026 update cycle (e.g., Adobe Commerce 2.4.9-2026-jul and Webhooks Plugin 1.21.0).

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats