
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21296 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce, Magento Open Source, and Commerce B2B that allows a low-privileged authenticated attacker to bypass security controls and gain limited unauthorized write access to data. The vulnerability affects Adobe Commerce and Magento Open Source versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Commerce B2B versions. It was disclosed on March 10–11, 2026, via Adobe's security advisory APSB26-05. The CVSS v3.1 base score is 4.3 (Medium) (Adobe Advisory).
The root cause is an Incorrect Authorization flaw (CWE-863), where the application fails to properly verify that an authenticated low-privileged user has the appropriate permissions before allowing certain operations. The attack vector is network-based, requires low privileges, and does not require user interaction, making it exploitable remotely by any authenticated user. The vulnerability results in a security feature bypass that allows limited unauthorized modification of data integrity. No specific technical write-ups or public proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation allows a low-privileged authenticated attacker to bypass authorization controls and make limited unauthorized modifications to data within the affected Adobe Commerce or Magento instance. The primary impact is on data integrity (low), with no direct confidentiality or availability impact per the CVSS scoring. While the scope is limited, unauthorized data modification in an e-commerce platform could affect product listings, pricing, or order data, potentially enabling fraud or business disruption (Adobe Advisory).
Adobe has released patched versions addressing this vulnerability as part of security advisory APSB26-05, published March 10, 2026. Administrators should upgrade to the following fixed releases: Adobe Commerce 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, or 2.4.9 (GA); Magento Open Source equivalent patched versions; and Commerce B2B corresponding patched releases. No configuration-based workarounds are documented — upgrading to a patched version is the recommended remediation (Adobe Advisory).
Adobe's advisory APSB26-05 was picked up by several security aggregators and monitoring services shortly after publication, including CIS, BeyondMachines, and various CVE tracking platforms. No notable independent researcher commentary or significant social media discussion has been identified beyond routine CVE tracking. The vulnerability's medium severity and requirement for authenticated access have limited broader community attention (Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."