Description
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Severity (CVSS)
| Base score | 3.7 |
|---|---|
| Severity | Low |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| Provided by | CNA |
Weaknesses
- CWE-200 — Information Exposure (CWE-200)
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Adobe Commerce | 0 to <=2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul |
| Adobe | Adobe Commerce B2B | 0 to <=1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul |
| Adobe | Magento Open Source | 0 to <=2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul |
| Adobe | Adobe Commerce Webhooks Plugin | 0 to <=1.20.0; 1.21.0 |
References
- https://helpx.adobe.com/security/products/magento/apsb26-73.html (vendor-advisory)
Generated from the official CVE List on 15 Jul 2026 07:06 UTC.