CVE-2026-76202
massIncorrect Authorization in Adobe Commerce Enables Privilege Escalation
Adobe Commerce, Adobe Commerce B2B, and Magento are affected by an incorrect authorization flaw (CWE-863) in which a resource or action is not properly restricted to the intended privileged actors. Because the issue is reachable over the network and requires no privileges or user interaction, a remote attacker can trigger it directly against a vulnerable storefront. Successful exploitation yields privilege escalation, giving the attacker elevated access to sensitive information with limited integrity impact. Any organization running an affected version of Adobe Commerce, Commerce B2B, or Magento is in scope. As of now there is no known in-the-wild exploitation, no public proof of concept, and the flaw is not in CISA's KEV catalog, with an EPSS 30-day exploitation probability of about 0.4%.
What to do: Check Adobe's security bulletin (from [email protected]) for this CVE and upgrade all Adobe Commerce, Commerce B2B, and Magento instances to the patched releases it specifies, prioritizing internet-facing storefronts. Until patching is complete, review authorization checks and restrict external access to sensitive store APIs and endpoints, and monitor Adobe Commerce/Magento logs for signs of anomalous privileged access. Since exact fixed versions are not in the available data, do not assume a release is safe until the bulletin's affected/fixed ranges are confirmed.
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| Adobe Magento | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.