Server-Side Request Forgery (SSRF) in Adobe products - CVE-2026-34647

 

Server-Side Request Forgery (SSRF) in Adobe products - CVE-2026-34647

Published: May 12, 2026


Vulnerability identifier: #VU131227
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-34647
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Adobe Commerce B2B
Magento Open Source
Adobe Commerce (formerly Magento Commerce)

How to mitigate CVE-2026-34647

Install updates from vendor's website.

Adobe Commerce B2B - addressed in versions 1.3.3-p18, 1.3.4-p17, 1.4.2-p10, 1.5.2-p5, 1.5.3
Magento Open Source - addressed in versions 2.4.6-p15, 2.4.7-p10, 2.4.8-p5, 2.4.9
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4-p18, 2.4.5-p17, 2.4.6-p15, 2.4.7-p10, 2.4.8-p5, 2.4.9

External References

Related Security Bulletins