CVE-2026-47998 Details
Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
A vulnerability has been identified in Adobe Commerce that involves incorrect authorization, potentially allowing for a security feature bypass. This issue could enable an attacker to circumvent security measures and gain unauthorized read access. The exploitation of this vulnerability depends on conditions beyond the attacker's control, and does not require user interaction. Affected versions include Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, 2.4.4-p18 and earlier, as well as Adobe Commerce B2B versions 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier.
Users are advised to update to Adobe Commerce versions 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, or 2.4.4-2026-jul. For Adobe Commerce B2B, update to versions 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, or 1.3.3-2026-jul.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/magento/apsb26-73.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe commerce | 2.4.4 - 2.4.4 p1 2.4.4 p10 2.4.4 p11 2.4.4 p12 2.4.4 p13 2.4.4 p14 2.4.4 p15 2.4.4 p16 2.4.4 p17 2.4.4 p18 2.4.4 p2 2.4.4 p3 2.4.4 p4 2.4.4 p5 2.4.4 p6 2.4.4 p7 2.4.4 p8 2.4.4 p9 2.4.5 - 2.4.5 p1 2.4.5 p10 2.4.5 p11 2.4.5 p12 2.4.5 p13 2.4.5 p14 2.4.5 p15 2.4.5 p16 2.4.5 p17 2.4.5 p2 2.4.5 p3 2.4.5 p4 2.4.5 p5 2.4.5 p6 2.4.5 p7 2.4.5 p8 2.4.5 p9 2.4.6 - 2.4.6 p1 2.4.6 p10 2.4.6 p11 2.4.6 p12 2.4.6 p13 2.4.6 p14 2.4.6 p15 2.4.6 p2 2.4.6 p3 2.4.6 p4 2.4.6 p5 2.4.6 p6 2.4.6 p7 2.4.6 p8 2.4.6 p9 2.4.7 - 2.4.7 b1 2.4.7 b2 2.4.7 beta3 2.4.7 p1 2.4.7 p10 2.4.7 p2 2.4.7 p3 2.4.7 p4 2.4.7 p5 2.4.7 p6 2.4.7 p7 2.4.7 p8 2.4.7 p9 2.4.8 - 2.4.8 beta1 2.4.8 beta2 2.4.8 p1 2.4.8 p2 2.4.8 p3 2.4.8 p4 2.4.8 p5 2.4.9 - |
CPE
Remediation
| |
| adobe commerce b2b | 1.3.3 - 1.3.3 p1 1.3.3 p10 1.3.3 p11 1.3.3 p12 1.3.3 p13 1.3.3 p14 1.3.3 p15 1.3.3 p16 1.3.3 p17 1.3.3 p18 1.3.3 p2 1.3.3 p3 1.3.3 p4 1.3.3 p5 1.3.3 p6 1.3.3 p7 1.3.3 p8 1.3.3 p9 1.3.4 - 1.3.4 p1 1.3.4 p10 1.3.4 p11 1.3.4 p12 1.3.4 p13 1.3.4 p14 1.3.4 p15 1.3.4 p16 1.3.4 p17 1.3.4 p2 1.3.4 p3 1.3.4 p4 1.3.4 p5 1.3.4 p6 1.3.4 p7 1.3.4 p8 1.3.4 p9 1.4.2 - 1.4.2 p1 1.4.2 p10 1.4.2 p2 1.4.2 p3 1.4.2 p4 1.4.2 p5 1.4.2 p6 1.4.2 p7 1.4.2 p8 1.4.2 p9 1.5.2 - 1.5.2 p1 1.5.2 p2 1.5.2 p3 1.5.2 p4 1.5.2 p5 1.5.3 - |
CPE
Remediation
| |
| adobe magento | 2.4.6 - 2.4.6 p1 2.4.6 p10 2.4.6 p11 2.4.6 p12 2.4.6 p13 2.4.6 p14 2.4.6 p15 2.4.6 p2 2.4.6 p3 2.4.6 p4 2.4.6 p5 2.4.6 p6 2.4.6 p7 2.4.6 p8 2.4.6 p9 2.4.7 - 2.4.7 b1 2.4.7 b2 2.4.7 beta3 2.4.7 p1 2.4.7 p10 2.4.7 p2 2.4.7 p3 2.4.7 p4 2.4.7 p5 2.4.7 p6 2.4.7 p7 2.4.7 p8 2.4.7 p9 2.4.8 - 2.4.8 beta1 2.4.8 beta2 2.4.8 p1 2.4.8 p2 2.4.8 p3 2.4.8 p4 2.4.8 p5 2.4.9 - |
CPE
Remediation
| |
| adobe i/o events | >= 1.6.0, < 1.21.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | CVE Modified | [email protected] |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |