
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21286 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce and Magento Open Source that allows unauthenticated remote attackers to bypass security controls and gain limited unauthorized read access to data. The vulnerability affects Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Adobe Commerce B2B and Magento Open Source releases. Adobe disclosed and patched this vulnerability on March 10–11, 2026, via Security Bulletin APSB26-05. It carries a CVSS v3.1 base score of 5.3 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to properly verify whether a requesting party has the appropriate permissions before granting access to certain data. The attack vector is network-based with low attack complexity, requiring no privileges and no user interaction, making it exploitable by any unauthenticated remote attacker. The flaw results in a security feature bypass that exposes limited data to unauthorized parties, though the precise endpoint or code path involved has not been publicly detailed beyond the vendor advisory (Adobe Advisory).
Successful exploitation allows an unauthenticated network attacker to bypass authorization controls and gain limited unauthorized read access to data within the affected Adobe Commerce or Magento Open Source instance. The impact is confined to confidentiality (low), with no integrity or availability impact reported. While the scope of exposed data is described as limited, e-commerce platforms may store sensitive customer, order, or business data that could be partially exposed (Adobe Advisory).
Adobe has released patched versions addressing this vulnerability. Administrators should upgrade to the following fixed releases or later: Adobe Commerce 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, or 2.4.9 (GA); corresponding Magento Open Source and Commerce B2B releases are also addressed. No configuration-based workaround has been published; upgrading to a patched version is the recommended remediation. Refer to Adobe Security Bulletin APSB26-05 for the full patch matrix (Adobe Advisory).
The vulnerability was noted in a CIS advisory covering multiple Adobe product patches released in March 2026, which flagged the broader patch batch as addressing issues that could allow for arbitrary code execution across various Adobe products. Community aggregators such as BeyondMachines and CVEFeed.io indexed the vulnerability shortly after disclosure, but no significant researcher commentary or media coverage specific to CVE-2026-21286 has been identified, consistent with its medium severity rating and lack of known exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."