CVE-2026-21285

EUVD-2026-11039
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
adobeCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
adobecommerce_b2b
𝑥
< 1.3.3
adobecommerce_b2b
1.3.3
adobecommerce_b2b
1.3.3:p1
adobecommerce_b2b
1.3.3:p10
adobecommerce_b2b
1.3.3:p11
adobecommerce_b2b
1.3.3:p12
adobecommerce_b2b
1.3.3:p13
adobecommerce_b2b
1.3.3:p14
adobecommerce_b2b
1.3.3:p15
adobecommerce_b2b
1.3.3:p16
adobecommerce_b2b
1.3.3:p2
adobecommerce_b2b
1.3.3:p3
adobecommerce_b2b
1.3.3:p4
adobecommerce_b2b
1.3.3:p5
adobecommerce_b2b
1.3.3:p6
adobecommerce_b2b
1.3.3:p7
adobecommerce_b2b
1.3.3:p8
adobecommerce_b2b
1.3.3:p9
adobecommerce_b2b
1.3.4
adobecommerce_b2b
1.3.4:p1
adobecommerce_b2b
1.3.4:p10
adobecommerce_b2b
1.3.4:p11
adobecommerce_b2b
1.3.4:p12
adobecommerce_b2b
1.3.4:p13
adobecommerce_b2b
1.3.4:p14
adobecommerce_b2b
1.3.4:p15
adobecommerce_b2b
1.3.4:p2
adobecommerce_b2b
1.3.4:p3
adobecommerce_b2b
1.3.4:p4
adobecommerce_b2b
1.3.4:p5
adobecommerce_b2b
1.3.4:p6
adobecommerce_b2b
1.3.4:p7
adobecommerce_b2b
1.3.4:p8
adobecommerce_b2b
1.3.4:p9
adobecommerce_b2b
1.3.5
adobecommerce_b2b
1.3.5:p1
adobecommerce_b2b
1.3.5:p10
adobecommerce_b2b
1.3.5:p11
adobecommerce_b2b
1.3.5:p12
adobecommerce_b2b
1.3.5:p13
adobecommerce_b2b
1.3.5:p2
adobecommerce_b2b
1.3.5:p3
adobecommerce_b2b
1.3.5:p4
adobecommerce_b2b
1.3.5:p5
adobecommerce_b2b
1.3.5:p6
adobecommerce_b2b
1.3.5:p7
adobecommerce_b2b
1.3.5:p8
adobecommerce_b2b
1.3.5:p9
adobecommerce_b2b
1.4.2
adobecommerce_b2b
1.4.2:p1
adobecommerce_b2b
1.4.2:p2
adobecommerce_b2b
1.4.2:p3
adobecommerce_b2b
1.4.2:p4
adobecommerce_b2b
1.4.2:p5
adobecommerce_b2b
1.4.2:p6
adobecommerce_b2b
1.4.2:p7
adobecommerce_b2b
1.4.2:p8
adobecommerce_b2b
1.5.2
adobecommerce_b2b
1.5.2:p1
adobecommerce_b2b
1.5.2:p2
adobecommerce_b2b
1.5.2:p3
adobecommerce_b2b
1.5.3:alpha1
adobecommerce_b2b
1.5.3:alpha2
adobecommerce_b2b
1.5.3:alpha3
adobecommerce
𝑥
< 2.4.4
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p10
adobecommerce
2.4.4:p11
adobecommerce
2.4.4:p12
adobecommerce
2.4.4:p13
adobecommerce
2.4.4:p14
adobecommerce
2.4.4:p15
adobecommerce
2.4.4:p16
adobecommerce
2.4.4:p2
adobecommerce
2.4.4:p3
adobecommerce
2.4.4:p4
adobecommerce
2.4.4:p5
adobecommerce
2.4.4:p6
adobecommerce
2.4.4:p7
adobecommerce
2.4.4:p8
adobecommerce
2.4.4:p9
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobecommerce
2.4.5:p10
adobecommerce
2.4.5:p11
adobecommerce
2.4.5:p12
adobecommerce
2.4.5:p13
adobecommerce
2.4.5:p14
adobecommerce
2.4.5:p15
adobecommerce
2.4.5:p2
adobecommerce
2.4.5:p3
adobecommerce
2.4.5:p4
adobecommerce
2.4.5:p5
adobecommerce
2.4.5:p6
adobecommerce
2.4.5:p7
adobecommerce
2.4.5:p8
adobecommerce
2.4.5:p9
adobecommerce
2.4.6
adobecommerce
2.4.6:p1
adobecommerce
2.4.6:p10
adobecommerce
2.4.6:p11
adobecommerce
2.4.6:p12
adobecommerce
2.4.6:p13
adobecommerce
2.4.6:p2
adobecommerce
2.4.6:p3
adobecommerce
2.4.6:p4
adobecommerce
2.4.6:p5
adobecommerce
2.4.6:p6
adobecommerce
2.4.6:p7
adobecommerce
2.4.6:p8
adobecommerce
2.4.6:p9
adobecommerce
2.4.7
adobecommerce
2.4.7:b1
adobecommerce
2.4.7:b2
adobecommerce
2.4.7:beta3
adobecommerce
2.4.7:p1
adobecommerce
2.4.7:p2
adobecommerce
2.4.7:p3
adobecommerce
2.4.7:p4
adobecommerce
2.4.7:p5
adobecommerce
2.4.7:p6
adobecommerce
2.4.7:p7
adobecommerce
2.4.7:p8
adobecommerce
2.4.8
adobecommerce
2.4.8:beta1
adobecommerce
2.4.8:beta2
adobecommerce
2.4.8:p1
adobecommerce
2.4.8:p2
adobecommerce
2.4.8:p3
adobecommerce
2.4.9:alpha1
adobecommerce
2.4.9:alpha2
adobecommerce
2.4.9:alpha3
adobemagento
𝑥
< 2.4.5
adobemagento
2.4.5
adobemagento
2.4.5:p1
adobemagento
2.4.5:p10
adobemagento
2.4.5:p11
adobemagento
2.4.5:p12
adobemagento
2.4.5:p13
adobemagento
2.4.5:p14
adobemagento
2.4.5:p15
adobemagento
2.4.5:p2
adobemagento
2.4.5:p3
adobemagento
2.4.5:p4
adobemagento
2.4.5:p5
adobemagento
2.4.5:p6
adobemagento
2.4.5:p7
adobemagento
2.4.5:p8
adobemagento
2.4.5:p9
adobemagento
2.4.6
adobemagento
2.4.6:p1
adobemagento
2.4.6:p10
adobemagento
2.4.6:p11
adobemagento
2.4.6:p12
adobemagento
2.4.6:p13
adobemagento
2.4.6:p2
adobemagento
2.4.6:p3
adobemagento
2.4.6:p4
adobemagento
2.4.6:p5
adobemagento
2.4.6:p6
adobemagento
2.4.6:p7
adobemagento
2.4.6:p8
adobemagento
2.4.6:p9
adobemagento
2.4.7
adobemagento
2.4.7:b1
adobemagento
2.4.7:b2
adobemagento
2.4.7:beta3
adobemagento
2.4.7:p1
adobemagento
2.4.7:p2
adobemagento
2.4.7:p3
adobemagento
2.4.7:p4
adobemagento
2.4.7:p5
adobemagento
2.4.7:p6
adobemagento
2.4.7:p7
adobemagento
2.4.7:p8
adobemagento
2.4.8
adobemagento
2.4.8:beta1
adobemagento
2.4.8:beta2
adobemagento
2.4.8:p1
adobemagento
2.4.8:p2
adobemagento
2.4.8:p3
adobemagento
2.4.9:alpha3
𝑥
= Vulnerable software versions