Back

HIGH

Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)

Published May 12, 2026

Description

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published May 12, 2026
Updated Aug 27, 2026
Reserved Mar 30, 2026
CISA Vulnrichment
Updated May 13, 2026
NVD
Status Analyzed
Modified Aug 28, 2026
Red Hat
Severity n/a
Public date n/a