Back

MEDIUM

Adobe Commerce | Improper Input Validation (CWE-20)

Published Mar 11, 2026

Description

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to application availability. Exploitation of this issue does not require user interaction.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Mar 11, 2026
Updated Aug 27, 2026
Reserved Dec 12, 2025
CISA Vulnrichment
Updated Mar 11, 2026
NVD
Status Analyzed
Modified Aug 28, 2026
Red Hat
Severity n/a
Public date n/a