ZeroHour

CVE-2026-76202

mass

Incorrect Authorization in Adobe Commerce Enables Privilege Escalation

CVSS 3.1
8.2 high
EPSS
<1%p33
Published
()
Modified
AI analysis

Adobe Commerce, Adobe Commerce B2B, and Magento are affected by an incorrect authorization flaw (CWE-863) in which a resource or action is not properly restricted to the intended privileged actors. Because the issue is reachable over the network and requires no privileges or user interaction, a remote attacker can trigger it directly against a vulnerable storefront. Successful exploitation yields privilege escalation, giving the attacker elevated access to sensitive information with limited integrity impact. Any organization running an affected version of Adobe Commerce, Commerce B2B, or Magento is in scope. As of now there is no known in-the-wild exploitation, no public proof of concept, and the flaw is not in CISA's KEV catalog, with an EPSS 30-day exploitation probability of about 0.4%.

What to do: Check Adobe's security bulletin (from [email protected]) for this CVE and upgrade all Adobe Commerce, Commerce B2B, and Magento instances to the patched releases it specifies, prioritizing internet-facing storefronts. Until patching is complete, review authorization checks and restrict external access to sensitive store APIs and endpoints, and monitor Adobe Commerce/Magento logs for signs of anomalous privileged access. Since exact fixed versions are not in the available data, do not assume a release is safe until the bulletin's affected/fixed ranges are confirmed.

Affected
Adobe Commerce
Adobe Commerce B2B
Adobe Magento
Estimated exposure
mass≈100,000–300,000 storefronts worldwide (Magento-family deployments, including Adobe Commerce and B2B) — Public web-technology surveys have long ranked Magento/Adobe Commerce among the top self-hosted e-commerce platforms with on the order of 100k–300k live sites, and the affected products span the entire Magento family, though only a subset…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.