Incorrect Authorization Vulnerability in Adobe Commerce by Adobe
CVE-2026-48412
2.7LOW
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-48412?
Adobe Commerce is impacted by a flaw related to incorrect authorization mechanisms. This vulnerability allows an attacker with high privileges to potentially escalate their access, affording them greater control over restricted resources. Notably, exploitation does not necessitate interaction from users, thereby increasing the risk of unauthorized access to sensitive data.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce 0 <= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce B2B 0 <= 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul