CVE-2026-48415: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48415?
The severity of CVE-2026-48415 is high, with a CVSS score of 7.6.
How do I fix CVE-2026-48415?
To fix CVE-2026-48415, apply the latest security patches provided by Adobe for Adobe Commerce.
What impact does CVE-2026-48415 have on Adobe Commerce?
CVE-2026-48415 allows a low-privileged attacker to bypass security features, gaining unauthorized read and write access.
Who is affected by CVE-2026-48415?
Any user of Adobe Commerce could be affected by CVE-2026-48415 if they do not implement the recommended security updates.
What could be the consequences of exploiting CVE-2026-48415?
Exploitation of CVE-2026-48415 could lead to limited disruption of availability and unauthorized access to sensitive data.