Incorrect Authorization Vulnerability in Adobe Commerce Products
CVE-2026-21285
4.3MEDIUM
What is CVE-2026-21285?
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, and 2.4.4-p16 are susceptible to an Incorrect Authorization issue. This vulnerability allows a low-privileged attacker to bypass security controls, potentially gaining unauthorized access to specific features without requiring any user interaction. Addressing this vulnerability is crucial for maintaining the security integrity of affected systems.
Affected Version(s)
Adobe Commerce 0 <= 2.4.4-p16