Executive brief
Adobe Commerce, an enterprise e-commerce platform used by online retailers, is affected by an authorization flaw that allows low-privileged attackers to bypass security controls. An attacker could exploit this vulnerability to gain unauthorized read and write access without requiring any user interaction, potentially disrupting service availability and compromising sensitive data.
Technical details
This is an Incorrect Authorization (CWE-863) vulnerability in Adobe Commerce that allows a security feature bypass. A low-privileged attacker can leverage the flaw to circumvent authorization checks and obtain unauthorized read and write access to protected resources. The attack requires network access to the Commerce instance and can be executed by any authenticated low-privilege user, but exploitation does not require victim interaction. The vulnerability results in limited disruption to availability and potential unauthorized data access. Patches are expected to be available via Adobe security bulletin APSB26-92.
Affected products
- Adobe Commerce
Timeline
- 2026-08-11: disclosed