CVE-2026-34656
published 2026-05-12CVE-2026-34656: Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability…
PriorityP423medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.39%
31.4th percentile
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.4-p17 | — |
| adobe | commerce | < 2.4.4 | 2.4.4 |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce_b2b | < 1.3.3 | 1.3.3 |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | magento | < 2.4.6 | 2.4.6 |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q79h-qrw2-xqrf: Adobe Commerce versions 2
ghsa_unreviewed·2026-05-12
CVE-2026-34656 [MEDIUM] CWE-285 GHSA-q79h-qrw2-xqrf: Adobe Commerce versions 2
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
VulDB
Adobe Commerce improper authorization (apsb26-49)
vuldb·2026-05-12
CVE-2026-34656 [CRITICAL] Adobe Commerce improper authorization (apsb26-49)
A vulnerability marked as critical has been reported in Adobe Commerce. The impacted element is an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-34656. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-12
Published