Improper Access Control in Adobe Commerce Products
CVE-2026-21289
7.5HIGH
What is CVE-2026-21289?
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, and earlier are impacted by an incorrect authorization issue, which allows attackers to bypass established security measures. This vulnerability enables unauthorized access to sensitive data without the need for user interaction, putting businesses at risk of data exposure and potential exploitation. Users are urged to review their systems and apply necessary updates to mitigate this security risk.
Affected Version(s)
Adobe Commerce 0 <= 2.4.4-p16