# CVE-2026-34654

## Summary

- **CVE ID:** CVE-2026-34654
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-1395
- **Published:** May 12, 2026
- **Last Modified:** Aug 28, 2026

## Description

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

## Affected Products

- Adobe — Adobe Commerce (0)
- Adobe — Adobe Commerce (2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18)
- Adobe — Adobe Commerce B2B (0)
- Adobe — Adobe Commerce B2B (1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18)
- Adobe — Magento Open Source (0)
- Adobe — Magento Open Source (2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15)

## References

- [CNA](https://helpx.adobe.com/security/products/magento/apsb26-49.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.62%
- **EPSS Percentile:** 47.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._