CVE-2026-77108
massIncorrect Authorization in Adobe Commerce (Magento) Enables Privilege Escalation
CVE-2026-77108, assigned by Adobe's PSIRT, is an Incorrect Authorization (CWE-863) flaw in Adobe Commerce, Adobe Commerce B2B, and Magento that can lead to privilege escalation. Per Adobe, an attacker can leverage the flaw to gain elevated access to sensitive information, and the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N, C:H/I:N/A:N) indicates it is reachable over the network without credentials or user interaction, with confidentiality-only impact. Store operators running the affected Adobe Commerce/Magento releases are in scope, though the affected and fixed version ranges are published in Adobe's advisory and are not included in this dataset. There is no public PoC, the CVE is not in CISA KEV, and EPSS estimates only about a 0.5% probability of exploitation in the next 30 days (40th percentile), so no exploitation is currently known.
What to do: Upgrade Adobe Commerce, Adobe Commerce B2B, and Magento to the fixed release identified in Adobe's security bulletin for this CVE (exact versions are in the advisory, not in this dataset), prioritizing internet-facing storefronts and API endpoints. Until patched, review role/permission and authorization configurations and audit access logs for signs of unauthorized elevated access to sensitive data. Monitor EPSS and CISA KEV for changes, since no exploitation or public PoC is known at this time.
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| adobe Magento | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.