UPSTREAM FIX

magento2-40459: REST attribute update failing without attribute_id

Community fix magento2-40459 merged into magento/magento2 on 2026-06-25, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.

Fixes the REST attribute update failing without attribute_id edited

Pull request title
REST API Attribute Update fails without attribute_id
Pull request
magento/magento2#40459
Issues
#40458 human
Author
@cmuench
Merged
2026-06-25
Fixed in
no release yet
Reported on
2.4.8-p3
Categories
Web API
Components
magento/module-catalog

Labels

Area
APIs
Component
Api
Priority
P2
Severity
—
Reported on (labels)
2.4.8-p3

Issue

Title and steps come from the upstream issue and pull request.

Description

Response 400 Bad Request:

Steps to reproduce

Update without attribute_id
1. Send a PUT request to /V1/products/attributes/{attributeCode}.
2. In the payload, include attribute_code but omit attribute_id.

Can be tested e.g. with the "color" attribute.

Expected result

The API should recognize the existing attribute by attribute_code from the URL and perform an update.

Actual result

Response 400 Bad Request:
{
  "message": "%1 already exists.",
  "parameters": [
    "Attribute with the same code"
  ]
}

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: test files do not apply to this releaseunit: could not run before, could not run after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseunit: could not run before, could not run after
2.4.9
2.4.9 clean
2.4.9: passes before (after: error)unit: passes before, could not run after

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 97.8%. Probability it is security relevant: 0.7%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 95.9%, refactor 1.3%, feature 1.0%, tests_only 0.9%, dependency 0.5%, docs_only 0.4%90.3%
Areacatalogcatalog 64.3%, graphql_api 31.1%, admin 1.8%44.1%
Reported version2.4.8-p32.4.8-p3 62.9%, 2.4.8 4.8%, 2.4.8-p4 1.7%39.3%
Scope1.25 of 21 45.0%, 2 39.8%, 0 15.3%7.6%
Risk0.42 of 20 64.1%, 1 29.9%, 2 6.0%25.5%
Worth backporting1.59 of 22 66.9%, 1 25.2%, 0 8.0%27.5%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40459/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-catalog
Bundle README (what the ZIP ships)
# magento2-40459

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40459
Issue: https://github.com/magento/magento2/issues/40458
Author: @cmuench
Source commit: a0348c6fb44ab48b73ec27daa8c76a4dfb19a260
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.