{"id":17693,"date":"2026-08-13T08:53:20","date_gmt":"2026-08-13T08:53:20","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17693"},"modified":"2026-08-13T08:53:20","modified_gmt":"2026-08-13T08:53:20","slug":"vital-adobe-commerce-flaw-lets-unauthenticated-attackers-escalate-privileges","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17693","title":{"rendered":"Vital Adobe Commerce Flaw Lets Unauthenticated Attackers Escalate Privileges"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">Adobe has launched safety updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Supply to handle a number of crucial vulnerabilities. <\/p>\n<p class=\"wp-block-paragraph\">One of the vital critical points is a<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/adobe-patches-multiple-security-flaw-in-flash-player\/\" data-type=\"post\" data-id=\"9878\" target=\"_blank\" rel=\"noreferrer noopener\"> high-impact privilege-escalation flaw<\/a>, tracked as CVE-2026-71362, which could be exploited with out authentication. <\/p>\n<p class=\"wp-block-paragraph\">This vulnerability arises from incorrect authorization controls and has a CVSS base rating of 9.1 out of 10. Adobe warns that profitable exploitation may enable attackers to bypass safety measures, execute arbitrary code, or elevate privileges inside susceptible e-commerce environments.<\/p>\n<h2 id=\"h-critical-adobe-commerce-flaw\" class=\"wp-block-heading\"><strong>Vital Adobe Commerce Flaw<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Essentially the most extreme flaw impacts Adobe Commerce installations working the July 2026 security-update builds and earlier, particularly variations 2.4.4 by means of 2.4.9. <\/p>\n<p class=\"wp-block-paragraph\">The vulnerability has the CVSS vector CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N, indicating that it&#8217;s remotely exploitable, requires no attacker privileges or person interplay, and might considerably influence on confidentiality and integrity. <\/p>\n<p class=\"wp-block-paragraph\">Whereas availability will not be straight affected, an attacker with elevated permissions may entry delicate retailer information, modify utility settings, or set up a foothold for additional compromise.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/helpx.adobe.com\/security\/products\/magento\/apsb26-92.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Adobe\u2019s bulletin APSB26-92,<\/a> launched on August 11, 2026, additionally addresses a number of different crucial points, together with authorization flaws and saved cross-site scripting (XSS) vulnerabilities. <\/p>\n<p class=\"wp-block-paragraph\">One notable unauthenticated incorrect-authorization vulnerability, CVE-2026-48416, is rated 7.5 and might trigger a security-feature bypass. <\/p>\n<p class=\"wp-block-paragraph\">Though it&#8217;s not as extreme as CVE-2026-71362, its lack of authentication necessities makes it significantly regarding for internet-facing storefronts and administrative interfaces. Safety researcher Wohlie reported this flaw.<\/p>\n<p class=\"wp-block-paragraph\">Two saved XSS vulnerabilities, CVE-2026-48413 and CVE-2026-48414, can result in <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/adobe-coldfusion-critical-vulnerabilities-2\/\" data-type=\"post\" data-id=\"195501\" target=\"_blank\" rel=\"noreferrer noopener\">arbitrary code execution<\/a> underneath sure circumstances. CVE-2026-48413 has a CVSS rating of 8.7 and requires low-privilege authentication and person interplay. <\/p>\n<p class=\"wp-block-paragraph\">On the identical time, CVE-2026-48414 is rated 7.7 and moreover requires administrative privileges. Adobe has additionally patched CVE-2026-48415, a crucial security-feature bypass challenge affecting the Adobe Commerce B2B part, together with two lower-severity authorization flaws, CVE-2026-48411 and CVE-2026-48412.<\/p>\n<p class=\"wp-block-paragraph\">Organizations are urged to improve instantly to the August 2026 builds. Adobe Commerce customers ought to replace to one of many following variations: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, or 2.4.4-2026-aug, relying on their supported launch department. <\/p>\n<p class=\"wp-block-paragraph\">Adobe Commerce B2B customers ought to apply the corresponding packages from 1.3.3 to 1.5.3 for August 2026, whereas Magento Open Supply customers ought to replace their supported deployments from 2.4.6 to 2.4.9.<\/p>\n<p class=\"wp-block-paragraph\">Adobe has assigned the replace a Precedence 2 score and said that it&#8217;s not conscious of any exploitation of the vulnerabilities addressed by APSB26-92 within the wild. <\/p>\n<p class=\"wp-block-paragraph\">Nevertheless, as a result of unauthenticated nature and low assault complexity of CVE-2026-71362, immediate patching is essential. Directors also needs to evaluate privileged account exercise, examine sudden configuration modifications, validate extension integrity, and make sure that acceptable internet utility firewalls and entry management insurance policies shield uncovered Commerce cases.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Cease new phishing &amp; malware earlier than they compromise your online business.\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/any.run\/threat-intelligence-feeds\/?utm_source=csn&amp;utm_medium=link+placement&amp;utm_campaign=stop+new+phishing&amp;utm_content=ti+feeds+sales&amp;utm_term=050826#contact-sales\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Combine reside intel from 15K SOCs all over the world<\/a><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Adobe has launched safety updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Supply to handle a number of crucial vulnerabilities. One of the vital critical points is a high-impact privilege-escalation flaw, tracked as CVE-2026-71362, which could be exploited with out authentication. This vulnerability arises from incorrect authorization controls and has a CVSS base [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17695,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[7649,1629,4962,420,2924,2705,265,374,6999],"class_list":["post-17693","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-adobe","tag-attackers","tag-commerce","tag-critical","tag-escalate","tag-flaw","tag-lets","tag-privileges","tag-unauthenticated"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17693"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17693\/revisions"}],"predecessor-version":[{"id":17694,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17693\/revisions\/17694"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17695"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17693"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-13 15:18:37 UTC -->