CVE-2026-34656: Adobe Commerce | Improper Authorization (CWE-285)
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34656?
CVE-2026-34656 has a medium severity rating due to the potential for unauthorized access and feature bypass.
How do I fix CVE-2026-34656?
To remediate CVE-2026-34656, update Adobe Commerce to a version later than 2.4.9-beta1.
Who is affected by CVE-2026-34656?
Adobe Commerce versions 2.4.9-beta1 and earlier, including 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, and 2.4.4-p17, are vulnerable to CVE-2026-34656.
What could an attacker achieve by exploiting CVE-2026-34656?
An attacker exploiting CVE-2026-34656 could bypass security features, potentially leading to unauthorized access to sensitive functionalities.
Is CVE-2026-34656 specific to a certain version of Adobe Commerce?
Yes, CVE-2026-34656 specifically affects Adobe Commerce versions up to and including 2.4.9-beta1.