ZeroHour

CVE-2026-77108

mass

Incorrect Authorization in Adobe Commerce (Magento) Enables Privilege Escalation

CVSS 3.1
7.5 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-77108, assigned by Adobe's PSIRT, is an Incorrect Authorization (CWE-863) flaw in Adobe Commerce, Adobe Commerce B2B, and Magento that can lead to privilege escalation. Per Adobe, an attacker can leverage the flaw to gain elevated access to sensitive information, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N, C:H/I:N/A:N) indicates it is reachable over the network without credentials or user interaction, with confidentiality-only impact. Store operators running the affected Adobe Commerce/Magento releases are in scope, though the affected and fixed version ranges are published in Adobe's advisory and are not included in this dataset. There is no public PoC, the CVE is not in CISA KEV, and EPSS estimates only about a 0.5% probability of exploitation in the next 30 days (40th percentile), so no exploitation is currently known.

What to do: Upgrade Adobe Commerce, Adobe Commerce B2B, and Magento to the fixed release identified in Adobe's security bulletin for this CVE (exact versions are in the advisory, not in this dataset), prioritizing internet-facing storefronts and API endpoints. Until patched, review role/permission and authorization configurations and audit access logs for signs of unauthorized elevated access to sensitive data. Monitor EPSS and CISA KEV for changes, since no exploitation or public PoC is known at this time.

Affected
Adobe Commerce
Adobe Commerce B2B
adobe Magento
Estimated exposure
masson the order of 100,000+ live Magento/Adobe Commerce storefronts, of which only a subset runs the affected versions — Public web-technology surveys (e.g., BuiltWith/W3Techs) have long counted Magento/Adobe Commerce at roughly 100k-200k live online stores, and because the flaw is network-reachable without authentication, any affected internet-facing…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.