Skip to content
AdobeCVE-2026-48415

Adobe Commerce: improper authorization

High7.6CVE-2026-48415 · Published Aug 11, 2026 · updated Sep 25, 2026

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

Adobe advisory

Affected versions

PackageAffectedFixed in
Adobe Commerce
Product
<= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aNo fix yet
Adobe Commerce B2B
Product
<= 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jNo fix yet
Magento Open Source
Product
<= 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Adobe advisories

All Adobe
Advisory
Adobe Campaign Classic: improper authorization
Critical10.0Aug 11
Adobe Commerce: improper authorization
Critical9.1Aug 11
Adobe Lightroom Classic: improper authorization
High7.7Aug 11
Adobe Lightroom Classic: path traversal
High8.6Aug 11
Adobe Commerce: cross-site scripting
High8.7Aug 11
Adobe Commerce: cross-site scripting
High7.7Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.