Disclosure
Adobe Commerce | Incorrect Authorization (CWE-863)
CVE: CVE-2026-21309
PT-Identifier: PT-2026-24562
Vendor: Adobe
Product: Adobe Commerce
CVSS: 7.5
Credits: n/a
Description:
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of data. Exploitation of this issue does not require user interaction.
References:
• https://dbugs.ptsecurity.com/vulnerability/CVE-2026-21309
• https://helpx.adobe.com/security/products/magento/apsb26-05.html
#dbugs_vuln
Post summary
The text discloses a new Incorrect Authorization (CWE‑863) vulnerability in Adobe Commerce, detailing affected versions and CVSS score, while also linking to a vendor advisory that presumably contains patch information. No PoC, exploit code, or active exploitation claims are present.