
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21297 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce and Magento Open Source that allows a low-privileged authenticated attacker to bypass security features and gain limited unauthorized access. Disclosed on March 10–11, 2026, as part of Adobe's March 2026 security update (APSB26-05), the vulnerability affects Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9-alpha3, including all patch releases up to 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, and 2.4.9-alpha3, as well as Adobe Commerce B2B across multiple versions. It carries a CVSS v3.1 base score of 4.3 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to properly verify whether an authenticated user has the appropriate permissions before granting access to a specific feature or resource. An attacker with low-privilege network access can exploit this flaw without any user interaction, leveraging the improper privilege validation mechanism to circumvent access controls. The attack vector is network-based, requires low privileges, and has no user interaction requirement, making it straightforward to exploit for any authenticated user on the platform (Adobe Advisory).
Successful exploitation allows a low-privileged authenticated attacker to bypass security controls and gain limited unauthorized access to features or data that should be restricted to higher-privilege roles. The primary impact is on confidentiality (limited unauthorized data or feature access) with no direct impact on integrity or availability per the CVSS scoring. While the immediate impact is constrained, unauthorized feature access in an e-commerce platform could expose sensitive business or customer data and potentially serve as a stepping stone for further privilege escalation (Adobe Advisory).
Adobe has released patched versions addressing this vulnerability as part of the March 2026 security update (APSB26-05). Administrators should update to the following versions or later: Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, or 2.4.9 (GA); Magento Open Source equivalent patch releases; and Adobe Commerce B2B corresponding patched versions. As interim measures, restrict network access to administrative interfaces, enforce the principle of least privilege for all user accounts, and review access logs for suspicious activity from authenticated low-privilege accounts (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution and security feature bypass, recommending prompt patching (CIS Advisory). Community aggregators such as BeyondMachines and CVEFeed.io catalogued the vulnerability shortly after disclosure, but no significant researcher commentary or social media discussion has been observed beyond routine tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."