CVE-2026-21286

MEDIUM WAF: Low
CVSS 5.3 Published: 2026-03-11
CWE-863

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view access of data. Exploitation of this issue does not require user interaction.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
adobecommerce_b2bup to 1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3
adobecommerce_b2b1.3.3

References

Back to CVE Database