Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-12686: Adobe Commerce allows access to other companies' data
CVE-2026-12686
Summary
Adobe Commerce does not properly check user access to company data, which means an authenticated user could see or change sensitive information from other companies hosted on the same website. This could lead to unauthorized access to customer billing data and other sensitive information. To protect your data, update Adobe Commerce to the latest version and ensure you have proper security measures in place.
Original title
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. The appli...
Original description
An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted within the same subdomain environment. The application does not adequately verify whether the requested company ID belongs to the authenticated user’s session, resulting in a cross-tenant authorisation bypass. If this vulnerability is successfully exploited, it allows unauthorised access to sensitive customer information, including billing data, and may enable the unauthorised modification of third-party data.
nvd CVSS4.0
9.3
Vulnerability type
CWE-639
Authorization Bypass Through User-Controlled Key
Published: 6 Jul 2026 · Updated: 23 Jul 2026 · First seen: 6 Jul 2026