CVE-2026-47992: Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47992?
CVE-2026-47992 has a severity rating of high with a score of 7.2.
How do I fix CVE-2026-47992?
To fix CVE-2026-47992, ensure that you apply the latest security patches provided by Adobe for Adobe Commerce.
What systems are affected by CVE-2026-47992?
CVE-2026-47992 affects Adobe Commerce, Adobe Commerce B2b, Adobe Magento, and Adobe I/o Events Commerce.
What type of vulnerability is CVE-2026-47992?
CVE-2026-47992 is classified as an SQL Injection vulnerability.
What could an attacker achieve by exploiting CVE-2026-47992?
An attacker could potentially execute arbitrary code in the context of the current user by exploiting CVE-2026-47992.