Adhoc Third-Party Dep Crash: Adobe Commerce <=2.4.9-beta1 (DOS)
CVE-2026-34652 Published on May 12, 2026

Adobe Commerce | Dependency on Vulnerable Third-Party Component (CWE-1395)
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-34652 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
HIGH

Weakness Type

CWE-1395

Products Associated with CVE-2026-34652

stack.watch emails you whenever new vulnerabilities are published in Adobe Commerce or Adobe Commerce. Just hit a watch button to start following.

 
 

Affected Versions

Adobe Commerce: