Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass

Vulnerability

A vulnerability has been identified in Adobe Commerce that involves incorrect authorization, potentially allowing for a security feature bypass. This issue could enable an attacker to circumvent security measures and gain unauthorized read access. The exploitation of this vulnerability depends on conditions beyond the attacker's control, and does not require user interaction. Affected versions include Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, 2.4.4-p18 and earlier, as well as Adobe Commerce B2B versions 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier.

Impact

Exploitation of this vulnerability could lead to unauthorized read access by bypassing security measures.

Remediation

Users are advised to update to Adobe Commerce versions 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, or 2.4.4-2026-jul. For Adobe Commerce B2B, update to versions 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, or 1.3.3-2026-jul.

Added: Jul 15, 2026, 5:32 AM
Updated: Jul 15, 2026, 5:32 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
7.2
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.