CVE-2026-34646: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34646?
CVE-2026-34646 has a medium severity level due to its potential for security feature bypass.
How do I fix CVE-2026-34646?
To fix CVE-2026-34646, update Adobe Commerce to the latest patched version beyond 2.4.9-beta1.
What versions of Adobe Commerce are affected by CVE-2026-34646?
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, and 2.4.4-p17 and earlier are affected by CVE-2026-34646.
What type of vulnerability is CVE-2026-34646?
CVE-2026-34646 is classified as an Incorrect Authorization vulnerability (CWE-863).
What could an attacker do with CVE-2026-34646?
An attacker could exploit CVE-2026-34646 to bypass security features and gain unauthorized access.