Description
Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce is affected by an Information Exposure vulnerability that can lead to a limited disclosure of sensitive data. The weakness is classified as CWE-200 and does not require user interaction to be exploited. Exploitation of this issue depends on conditions beyond the attacker’s direct control, indicating that the vulnerability is not easily reproducible by a generic attacker. The potential impact is the inadvertent exposure of data that could aid further attacks, but the scope is limited to information that is inadvertently revealed by the affected systems.

Affected Systems

Affected products include Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Adobe Magento Open Source. No specific version information was provided for the vulnerability, so all released versions of the listed products should be considered potentially impacted until a patch is released.

Risk and Exploitability

The CVSS score of 3.7 indicates a low overall severity, and the EPSS score of less than 1% suggests that an exploit is unlikely to be observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote access to a component that inadvertently exposes data, although no explicit network path is detailed in the advisory. The dependency on external conditions means the risk of exploitation today is very low, but continuous monitoring for new findings is advised.

Generated by OpenCVE AI on July 31, 2026 at 05:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Adobe's official security advisory for an updated patch or fix and apply it to all affected Commerce and Magento installations.
  • If a patch is not yet available, restrict network access to the Commerce Webhooks Plugin and any endpoints that may expose sensitive data, applying the principle of least privilege.
  • Review and tighten the configuration of Commerce instances to ensure that internal data is not inadvertently exposed to external requests.

Generated by OpenCVE AI on July 31, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source

Fri, 17 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Title Adobe Commerce | Information Exposure (CWE-200)
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Adobe Commerce Webhooks Plugin Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T14:26:32.819Z

Reserved: 2026-05-20T15:50:31.368Z

Link: CVE-2026-48001

cve-icon Vulnrichment

Updated: 2026-07-15T14:24:54.997Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:53:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor