CVE-2026-21309: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21309?
CVE-2026-21309 has been classified with a high severity level due to its potential for security feature bypass.
How do I fix CVE-2026-21309?
To mitigate CVE-2026-21309, update Adobe Commerce to the latest version beyond 2.4.9-alpha3, which addresses the incorrect authorization issue.
Which versions of Adobe Commerce are affected by CVE-2026-21309?
CVE-2026-21309 affects Adobe Commerce versions 2.4.9-alpha3 and earlier, including 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, and 2.4.4-p16.
What type of vulnerability is CVE-2026-21309?
CVE-2026-21309 is categorized as an Incorrect Authorization vulnerability, specifically related to CWE-863.
Who is affected by CVE-2026-21309?
Organizations using Adobe Commerce versions 2.4.9-alpha3 and earlier are at risk due to CVE-2026-21309.