Server-Side Request Forgery Vulnerability in Adobe Commerce
CVE-2026-21293
5.5MEDIUM
What is CVE-2026-21293?
Adobe Commerce is vulnerable to a Server-Side Request Forgery (SSRF) issue, which enables high-privileged attackers to manipulate server-side requests. This could facilitate unauthorized access to sensitive resources, effectively bypassing security features without requiring any user interaction. The flaw affects multiple versions of Adobe Commerce, emphasizing the need for timely updates and patches to protect sensitive data.
Affected Version(s)
Adobe Commerce 0 <= 2.4.4-p16