CVE-2026-47998: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47998?
The severity of CVE-2026-47998 is classified as medium with a score of 5.9.
What type of vulnerability is CVE-2026-47998?
CVE-2026-47998 is classified as an Incorrect Authorization vulnerability, which can lead to security feature bypass.
How do I fix CVE-2026-47998?
To fix CVE-2026-47998, ensure that all authorization checks are strictly enforced within the Adobe Commerce application.
What can an attacker do with CVE-2026-47998?
An attacker could exploit CVE-2026-47998 to bypass security measures and gain unauthorized read access to sensitive information.
Is exploitation of CVE-2026-47998 dependent on certain conditions?
Yes, the exploitation of CVE-2026-47998 is dependent on conditions that are typically beyond the attacker's control.