PT-2026-40394 · Adobe · Commerce

Published

2026-05-12

·

Updated

2026-05-12

·

CVE-2026-34649

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Adobe Commerce versions prior to 2.4.9-beta1
Description An uncontrolled resource consumption issue exists that could lead to an application denial-of-service. An attacker can exploit this to exhaust system resources, causing the application to become unavailable. This process does not require any user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2026-06640
CVE-2026-34649

Affected Products

Commerce