CVE-2026-21359: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited impact to the integrity and availability of data. The exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21359?
CVE-2026-21359 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2026-21359?
To remediate CVE-2026-21359, update Adobe Commerce to the latest version that does not include this vulnerability.
What kind of attacks can CVE-2026-21359 facilitate?
CVE-2026-21359 can allow attackers to bypass security features and gain unauthorized access to sensitive information.
Which versions of Adobe Commerce are affected by CVE-2026-21359?
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by CVE-2026-21359.
Is there a workaround for CVE-2026-21359 if immediate patching isn’t possible?
No official workaround for CVE-2026-21359 is provided, and it is recommended to update to a fixed version as soon as possible.