CVE-2026-47992
Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Record summary
CVE-2026-47992 has a selected CVSS score of 7.2 (high).
Description
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Adobe CommerceBrowse Adobe / Adobe CommerceDefault status: affected | CVE List | Through 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18 | affected |
| 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul | unaffected | ||
Adobe Commerce B2BBrowse Adobe / Adobe Commerce B2BDefault status: affected | CVE List | Through 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18 | affected |
| 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul | unaffected | ||
Adobe Commerce Webhooks PluginBrowse Adobe / Adobe Commerce Webhooks PluginDefault status: affected | CVE List | Through 1.20.0 | affected |
| 1.21.0 | unaffected | ||
Magento Open SourceBrowse Adobe / Magento Open SourceDefault status: affected | CVE List | Through 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15 | affected |
| 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul | unaffected |