CVE-2026-21297
Received
Received - Intake
Incorrect Authorization in Adobe Commerce Enables Security Bypass
Publication date: 2026-03-11
Last updated on: 2026-03-11
Assigner: Adobe Systems Incorporated
Description
Description
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | to 2.4.4 (exc) |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.8 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.8 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.8 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.8 |
| adobe | commerce | 2.4.9 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.8 |
| adobe | commerce | 2.4.9 |
| adobe | commerce | 2.4.4 |
| adobe | commerce | 2.4.5 |
| adobe | commerce | 2.4.6 |
| adobe | commerce | 2.4.7 |
| adobe | commerce | 2.4.8 |
| adobe | commerce | 2.4.9 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | to 1.3.3 (exc) |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.5.2 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.5.2 |
| adobe | commerce_b2b | 1.5.3 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.5.2 |
| adobe | commerce_b2b | 1.5.3 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.3.3 |
| adobe | commerce_b2b | 1.3.4 |
| adobe | commerce_b2b | 1.3.5 |
| adobe | commerce_b2b | 1.4.2 |
| adobe | commerce_b2b | 1.5.2 |
| adobe | commerce_b2b | 1.5.3 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.8 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.8 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.8 |
| adobe | magento | to 2.4.5 (exc) |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.8 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.8 |
| adobe | magento | 2.4.5 |
| adobe | magento | 2.4.6 |
| adobe | magento | 2.4.7 |
| adobe | magento | 2.4.8 |
| adobe | magento | 2.4.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |