NCSC-2026-0152: Multiple Vulnerabilities Fixed in Adobe Commerce (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Adobe Commerce 2.4.9-beta1 and earlier affected
- Incorrect Authorization allows write access without user interaction
- SSRF requires user interaction, leads to read access
- Uncontrolled Resource Consumption causes denial of service
"Adobe has patched several vulnerabilities in Adobe Commerce, including an incorrect authorization flaw, a Server-Side Request Forgery (SSRF) issue, and an uncontrolled resource consumption bug. These affect versions up to 2.4.9-beta1 and could lead to unauthorized write access, information disclosure, or denial of service."
no comments yet.