Junglewise Threat Intelligence

CVE-2026-48001: Adobe Commerce information exposure vulnerability

CVE-2026-48001 · Severity: low · CVSS 3.7 · Published 2026-07-14

Executive brief

Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a vulnerability that could allow the disclosure of sensitive information. An attacker could potentially access data they are not authorized to see, though the exploit requires specific conditions outside of the attacker's direct control. This issue does not require any interaction from a legitimate user to be exploited.

Technical details

Adobe Commerce and Magento Open Source are vulnerable to an information exposure (CWE-200) flaw. The vulnerability allows an unauthenticated attacker to potentially access sensitive information over the network. Exploitation is considered difficult (AC:H) as it depends on specific environmental conditions or configurations beyond the attacker's direct control. No user interaction is required for successful exploitation. Adobe has released security updates to address this issue across multiple versions of Commerce, Magento Open Source, and the Webhooks Plugin.

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats