CVE-2026-21282: Adobe Commerce | Improper Input Validation (CWE-20)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to application availability. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21282?
CVE-2026-21282 is considered a significant vulnerability due to its potential to cause denial-of-service in affected Adobe Commerce versions.
How do I fix CVE-2026-21282?
To mitigate CVE-2026-21282, upgrade your Adobe Commerce installation to the latest version that resolves this input validation issue.
What versions are affected by CVE-2026-21282?
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, and 2.4.4-p16 and earlier are impacted by CVE-2026-21282.
What type of vulnerability is CVE-2026-21282?
CVE-2026-21282 is categorized as an Improper Input Validation vulnerability which can lead to a denial-of-service condition.
Can CVE-2026-21282 be exploited remotely?
Yes, an attacker can exploit CVE-2026-21282 remotely, potentially leading to application denial-of-service.