CVE-2026-34645
published 2026-05-12CVE-2026-34645: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.56%
42.7th percentile
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.4-p17 | — |
| adobe | commerce | < 2.4.4 | 2.4.4 |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce_b2b | < 1.3.3 | 1.3.3 |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | magento | < 2.4.6 | 2.4.6 |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cffg-9fwp-87hv: Adobe Commerce versions 2
ghsa_unreviewed·2026-05-12
CVE-2026-34645 [HIGH] CWE-863 GHSA-cffg-9fwp-87hv: Adobe Commerce versions 2
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
VulDB
Adobe Commerce authorization (apsb26-49)
vuldb·2026-05-12
CVE-2026-34645 [LOW] Adobe Commerce authorization (apsb26-49)
A vulnerability identified as problematic has been detected in Adobe Commerce. This affects an unknown part. The manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-34645. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published