Improper Input Validation in Adobe Commerce by Adobe
CVE-2026-34685

3.4LOW

Key Information:

Vendor

Adobe

Vendor
CVE Published:
12 May 2026

What is CVE-2026-34685?

Adobe Commerce is susceptible to an Improper Input Validation vulnerability that enables high-privileged attackers to bypass security features, allowing unauthorized write access. Exploitation requires user interaction, as victims must visit a specifically crafted malicious URL or interact with a compromised webpage. This vulnerability impacts several versions leading up to 2.4.9-beta1, necessitating immediate attention to maintain the integrity of the platform.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p17

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.