CVE-2026-34645: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34645?
The severity of CVE-2026-34645 is considered critically high due to the potential for security feature bypass.
How do I fix CVE-2026-34645?
To fix CVE-2026-34645, ensure that you update your Adobe Commerce version to a patched release that addresses this vulnerability.
Which versions of Adobe Commerce are affected by CVE-2026-34645?
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17, and earlier are affected by CVE-2026-34645.
What type of vulnerability is CVE-2026-34645?
CVE-2026-34645 is categorized as an Incorrect Authorization vulnerability under CWE-863.
Can CVE-2026-34645 be exploited for unauthorized access?
Yes, CVE-2026-34645 can be exploited by attackers to bypass security features and gain unauthorized access.