Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security flaw that allows unauthorized access to sensitive data. An attacker could bypass existing security controls to read or modify information without needing a valid account or any interaction from a legitimate user. This could lead to the theft of customer data or unauthorized changes to the store's operations.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and the Adobe Commerce Webhooks Plugin. The flaw allows a remote, unauthenticated attacker to bypass security features via the network. Successful exploitation grants unauthorized read and write access to the application's data and functionality. The vulnerability does not require user interaction and has a CVSS 3.1 base score of 8.6. Patches have been released in the July 2026 update cycle (e.g., Adobe Commerce 2.4.9-2026-jul and Webhooks Plugin 1.21.0).
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory