Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security flaw that could allow unauthorized access to sensitive information. An attacker could bypass existing security controls to read data they should not be able to see. While the attack does not require user interaction, it depends on specific environmental conditions to be successful.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Adobe Commerce, Magento Open Source, and related components. The flaw allows a remote attacker to bypass security features and gain unauthorized read access to sensitive data. The attack vector is network-based and requires no prior authentication or user interaction, though the complexity is rated as high because exploitation depends on conditions beyond the attacker's immediate control. Adobe has released patches for affected versions, including Adobe Commerce 2.4.x and the Webhooks Plugin.
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory