Uncontrolled Resource Consumption in Adobe Commerce Software
CVE-2026-34648
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-34648?
Adobe Commerce is susceptible to an Uncontrolled Resource Consumption vulnerability affecting specific versions, which allows an attacker to exploit system resources. This can lead to a denial-of-service condition, where the application becomes unavailable due to resource exhaustion. Notably, the exploitation does not require any user interaction, making it critical for users of affected versions to apply necessary patches and updates to mitigate potential risks.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17
Adobe Commerce B2B 0 <= 1.5.3-beta1, 1.5.2-p4, 1.4.2-p9, 1.3.4-p16, 1.3.3-p17
Magento Open Source 0 <= 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14
References
EPSS Score
22% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved