AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-48411

MEDIUM · CVSS 6.5 EPSS 0.49% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Adobe Commerce is vulnerable to an Incorrect Authorization flaw that allows attackers with high privileges to bypass security features, potentially leading to unauthorized write access. This vulnerability poses a medium risk as it can be exploited without user interaction. Organizations using Adobe Commerce should prioritize addressing this issue to mitigate the risk of unauthorized data manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48411
Severity
MEDIUM
CVSS
6.5
EPSS
0.49%

Original NVD Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.