CVE-2026-21289: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21289?
The severity of CVE-2026-21289 is classified as a medium risk due to potential security feature bypass.
How do I fix CVE-2026-21289?
To fix CVE-2026-21289, update Adobe Commerce to the latest version that addresses this vulnerability.
What versions are affected by CVE-2026-21289?
CVE-2026-21289 affects Adobe Commerce versions 2.4.9-alpha3 and earlier up to 2.4.4.
What kind of attack does CVE-2026-21289 facilitate?
CVE-2026-21289 can facilitate unauthorized access through a security feature bypass.
How can I determine if my Adobe Commerce installation is vulnerable to CVE-2026-21289?
You can determine if your installation is vulnerable by checking the version against the list of affected releases for CVE-2026-21289.