MEDIUMVulnerability
CVE-2026-47996
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.
Properties
- severity
- MEDIUM
- score
- 6.8
- cve_id
- CVE-2026-47996
- vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- published_at
- 2026-07-14T20:17:04.840
- last_modified
- 2026-08-05T17:32:57.870
Related Entities (50)
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
AFFECTS_PRODUCT (48)
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
→[Product]
Explore deeper with Ninja Signal's threat intelligence graph