AdobeCVE-2026-48412
Adobe Commerce: improper authorization
Low2.7CVE-2026-48412 · Published Aug 11, 2026 · updated Sep 25, 2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Adobe Commerce Product | <= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-a | No fix yet |
| Adobe Commerce B2B Product | <= 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-j | No fix yet |
| Magento Open Source Product | <= 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-j | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Adobe Campaign Classic: improper authorization | Critical10.0 | No fix yet |
| Aug 11 | Adobe Commerce: improper authorization | Critical9.1 | No fix yet |
| Aug 11 | Adobe Lightroom Classic: improper authorization | High7.7 | No fix yet |
| Aug 11 | Adobe Lightroom Classic: path traversal | High8.6 | No fix yet |
| Aug 11 | Adobe Commerce: cross-site scripting | High8.7 | No fix yet |
| Aug 11 | Adobe Commerce: cross-site scripting | High7.7 | No fix yet |