
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21359 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce and Magento Open Source that could result in a security feature bypass. Affected versions include Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Magento Open Source and Adobe Commerce B2B releases. The vulnerability was disclosed on March 10–11, 2026, via Adobe security bulletin APSB26-05. It carries a CVSS v3.1 base score of 4.7 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to properly verify whether a requester has the appropriate permissions to access a resource or perform an action. An unauthenticated remote attacker can exploit this over the network to bypass security controls, though exploitation depends on conditions beyond the attacker's control and requires user interaction (per the CVSS vector AV:N/AC:H/PR:N/UI:R/S:C). The high attack complexity and dependency on external conditions significantly limit the exploitability window. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation results in a limited security feature bypass with low impact to both integrity and availability of data; there is no confidentiality impact. An attacker could potentially manipulate or disrupt data within the affected Adobe Commerce or Magento instance, but the scope of impact is constrained by the high attack complexity and required environmental conditions. The changed scope indicator suggests the impact may extend beyond the vulnerable component itself, though lateral movement potential is limited given the overall low severity (Adobe Advisory).
Adobe has released patches addressing this vulnerability as part of security bulletin APSB26-05 (released March 10, 2026). Administrators should upgrade to the following fixed versions: Adobe Commerce 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, or 2.4.4-p17 (or later), and apply corresponding Magento Open Source and Commerce B2B patches. As a general hardening measure, review and audit access control and authorization configurations within your Adobe Commerce deployment, and monitor for suspicious activity targeting authorization-sensitive endpoints (Adobe Advisory).
Adobe published the official security bulletin APSB26-05 on March 10, 2026, addressing this and other vulnerabilities in Adobe Commerce and Magento. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Adobe products that could allow for arbitrary code execution, referencing this bulletin. Community coverage has been limited given the medium severity and lack of public exploit code, with automated vulnerability tracking services (CVEFeed, VulDB, CIRCL) indexing the issue shortly after disclosure (CIS Advisory, Adobe Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."