helpx.adobe.comVendor advisory
https://helpx.adobe.com/security/products/magento/apsb26-92.html CVE-2026-48416
HIGH
Adobe Commerce | Incorrect Authorization (CWE-863)
Record summary
CVE-2026-48416 has a selected CVSS score of 7.5 (high).
Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Adobe CommerceBrowse Adobe / Adobe CommerceDefault status: affected | CVE List | Through 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | affected |
| 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | unaffected | ||
Adobe Commerce B2BBrowse Adobe / Adobe Commerce B2BDefault status: affected | CVE List | Through 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul | affected |
| 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug | unaffected | ||
Magento Open SourceBrowse Adobe / Magento Open SourceDefault status: affected | CVE List | Through 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul | affected |
| 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug | unaffected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-48416