CVE-2026-21294
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and bypass security controls. Exploitation of this issue does not require user interaction.
Vendor
Product
CWE
Yayın Tarihi
2026-03-11 03:15:54
Güncelleme
2026-03-11 18:03:36
Source Identifier
psirt@adobe.com
KEV Date Added
-