---
id: CVE-2026-48412
title: >-
  Adobe Commerce is affected by an Incorrect Authorization vulnerability that
  could result in privilege escalation
summary: >-
  Adobe Commerce is affected by an Incorrect Authorization vulnerability that
  could result in privilege escalation. An attacker with high privileges could
  exploit this vulnerability to gain elevated access to restricted resources.
  Exploita…
severity: low
cvss: 2.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: adobe
product: commerce
affected:
  - commerce = 2.4.4
  - commerce = 2.4.5
  - commerce = 2.4.6
  - commerce = 2.4.7
  - commerce = 2.4.8
  - commerce = 2.4.9
  - magento = 2.4.6
  - magento = 2.4.7
  - magento = 2.4.8
  - magento = 2.4.9
  - commerce_b2b = 1.3.3
  - commerce_b2b = 1.3.4
  - commerce_b2b = 1.3.5
  - commerce_b2b = 1.4.2
published: '2026-08-11'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T16:11:44.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48412'
references:
  - url: 'https://helpx.adobe.com/security/products/magento/apsb26-92.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.0054
epssPercentile: 0.43066
ingestedAt: '2026-09-25T16:12:08.702Z'
---

## Overview

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.

## Affected

- `commerce = 2.4.4`
- `commerce = 2.4.5`
- `commerce = 2.4.6`
- `commerce = 2.4.7`
- `commerce = 2.4.8`
- `commerce = 2.4.9`
- `magento = 2.4.6`
- `magento = 2.4.7`
- `magento = 2.4.8`
- `magento = 2.4.9`
- `commerce_b2b = 1.3.3`
- `commerce_b2b = 1.3.4`
- `commerce_b2b = 1.3.5`
- `commerce_b2b = 1.4.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
