CVE-2026-21286: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view access of data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21286?
CVE-2026-21286 has a high severity rating due to its potential for security feature bypass through incorrect authorization.
How do I fix CVE-2026-21286?
To fix CVE-2026-21286, upgrade your Adobe Commerce version to 2.4.9-alpha4 or later.
What versions of Adobe Commerce are affected by CVE-2026-21286?
CVE-2026-21286 affects Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier.
What type of vulnerability is CVE-2026-21286 classified as?
CVE-2026-21286 is classified as an Incorrect Authorization vulnerability.
What could an attacker exploit in CVE-2026-21286?
An attacker could exploit CVE-2026-21286 to bypass security features and potentially gain unauthorized access.