Junglewise Threat Intelligence

CVE-2026-47996: Adobe Commerce incorrect authorization security bypass

CVE-2026-47996 · Severity: high · CVSS 7.6 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source, Adobe Commerce B2b, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce and Magento Open Source, popular e-commerce platforms used for online storefronts, are affected by a security bypass vulnerability. An attacker with high-level administrative privileges can exploit this flaw to bypass existing security controls and access sensitive data they should not be able to see. This could lead to the exposure of confidential business information or customer data, though it requires the attacker to already have a significant level of access to the system.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and related plugins. The flaw allows a high-privileged attacker to bypass security features and gain unauthorized read access to restricted data. The attack vector is network-based and requires no user interaction, though it does require high-level administrative permissions (PR:H). The vulnerability is notable for a change in scope (S:C), indicating the impact may extend beyond the immediate software component. Patches have been released in the July 2026 security updates (e.g., Adobe Commerce 2.4.9-2026-jul).

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats