Junglewise Threat Intelligence

CVE-2026-47997: Adobe Commerce incorrect authorization security bypass

CVE-2026-47997 · Severity: medium · CVSS 5.9 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source, Adobe Commerce B2b, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used for online storefronts, is affected by a security flaw that allows unauthorized access to information. An attacker could bypass existing security controls to read sensitive data without needing to log in or interact with a user. While the exploit depends on specific environmental conditions, it poses a risk to the confidentiality of business or customer information.

Technical details

An Incorrect Authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and related components. The flaw allows a remote, unauthenticated attacker to bypass security features and gain unauthorized read access to data. The attack vector is network-based, and while it requires no user interaction, the complexity is rated as high because successful exploitation depends on conditions beyond the attacker's immediate control. Affected versions include Adobe Commerce 2.4.9 and earlier; patches have been released in the July 2026 update cycle (e.g., version 2.4.9-2026-jul).

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats