CVE-2026-21297: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21297?
CVE-2026-21297 has a low severity rating as it primarily involves incorrect authorization leading to potential security feature bypass.
How do I fix CVE-2026-21297?
To fix CVE-2026-21297, upgrade to the latest version of Adobe Commerce beyond 2.4.9-alpha3.
Which versions of Adobe Commerce are affected by CVE-2026-21297?
CVE-2026-21297 affects Adobe Commerce versions 2.4.9-alpha3 and earlier, including 2.4.8-p3, 2.4.7-p8, and several others listed.
Can CVE-2026-21297 be exploited by low-privileged attackers?
Yes, a low-privileged attacker can exploit CVE-2026-21297 to potentially bypass security features.
Is CVE-2026-21297 a critical vulnerability?
No, CVE-2026-21297 is not considered critical but should still be addressed to prevent unauthorized access.