Executive brief
Adobe Commerce, a popular e-commerce platform used by retailers to manage online stores, contains an authorization flaw that allows attackers to bypass security controls and read unauthorized data. This vulnerability requires no user interaction and could enable attackers to access sensitive customer or business information without proper credentials.
Technical details
The vulnerability is an incorrect authorization flaw in Adobe Commerce that allows security feature bypass through unauthorized read access. The attack vector is network-based and requires no user interaction; an attacker can exploit this remotely by making crafted requests that circumvent authorization checks. The scope is changed, meaning an attacker can access resources beyond their normal privilege level. Patch availability and specific affected versions are not detailed in the available advisory content.
Affected products
- Adobe Commerce
Timeline
- 2026-09-08: disclosed