Junglewise Threat Intelligence

CVE-2026-48412: Adobe Commerce privilege escalation via incorrect authorization

CVE-2026-48412 · Severity: low · CVSS 2.7 · Published 2026-08-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an e-commerce platform used by retailers to manage online storefronts and sales operations. A privilege escalation vulnerability in the authorization system could allow high-privileged attackers to gain access to sensitive administrative functions and customer data. This vulnerability requires the attacker to already have elevated privileges and does not require user interaction to exploit.

Technical details

Adobe Commerce contains an Incorrect Authorization vulnerability (CWE-863) that fails to properly validate access controls for certain restricted resources. An attacker with high-level privileges can exploit improper authorization checks to gain elevated access beyond their intended permission level. The vulnerability is remotely accessible over the network and does not require additional user interaction. Successful exploitation enables privilege escalation, granting attackers access to administrative functionality and sensitive data they should not be able to access. Adobe has acknowledged the vulnerability and patches are expected; check APSB26-92 for availability.

Affected products

  • Adobe Commerce

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory: APSB26-92

References

Related threats