CVE-2026-48412: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48412?
The severity of CVE-2026-48412 is classified as low, with a score of 2.7.
How do I fix CVE-2026-48412?
To fix CVE-2026-48412, ensure that you implement proper authorization checks and review user privilege settings within Adobe Commerce.
What is the impact of CVE-2026-48412?
CVE-2026-48412 could result in privilege escalation, allowing an attacker with high privileges to access restricted resources.
Does CVE-2026-48412 require user interaction to exploit?
No, exploitation of CVE-2026-48412 does not require user interaction.
What type of vulnerability is CVE-2026-48412 classified as?
CVE-2026-48412 is classified as an Incorrect Authorization vulnerability according to CWE-863.