6.5mediumMedium
CVE-2026-48411
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an administrative account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 6.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H- Weakness
- CWE-863
- Assigned by
- psirt@adobe.com
Dates
- Published
- 2026-08-11
- Last modified
- 2026-08-28
- Sources
- NVD