CVE-2026-21285: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21285?
CVE-2026-21285 has a low severity rating due to the ability of low-privileged attackers to bypass security features.
How do I fix CVE-2026-21285?
To mitigate CVE-2026-21285, upgrade to Adobe Commerce versions 2.4.9-alpha4 or later and ensure that your system is properly configured to prevent unauthorized access.
What types of systems are affected by CVE-2026-21285?
CVE-2026-21285 affects Adobe Commerce versions 2.4.4 and earlier, including various B2B editions.
Can CVE-2026-21285 be exploited remotely?
Yes, CVE-2026-21285 can be exploited remotely by low-privileged attackers to bypass authorization mechanisms.
What specific functionality does CVE-2026-21285 compromise?
CVE-2026-21285 compromises security features, allowing unauthorized access to certain functionalities within Adobe Commerce.