ZeroHour

CVE-2026-77109

mass

Incorrect Authorization Privilege Escalation in Adobe Commerce / Magento

CVSS 3.1
8.6 high
EPSS
<1%p34
Published
()
Modified
AI analysis

Adobe Commerce, Adobe Commerce B2B, and Magento are affected by an incorrect authorization flaw (CWE-863) in the platform's access-control handling. Because the vector requires no prior privileges and no user interaction, a remote, unauthenticated attacker can trigger the issue directly over the network. Successful exploitation allows the attacker to gain elevated access to resources that should be restricted, resulting in a high-impact integrity compromise (the scope-change flag indicates a second authority boundary, such as the application vs. its data or admin scope, is affected). Any organization running the affected versions of these e-commerce platforms is exposed, with storefronts handling customer and order data the primary concern. There is currently no known public proof-of-concept, no listing in CISA's KEV catalog, and only a modest 0.4% 30-day exploitation probability (EPSS), so exploitation in the wild is not yet confirmed.

What to do: Patch by upgrading to the fixed release listed in Adobe's security bulletin for this CVE, since the source data does not specify exact version numbers; prioritize internet-exposed admin and API surfaces. Until patched, restrict network access to administrative and API endpoints and review logs for unexpected privilege changes or access to restricted resources. Track Adobe's bulletin for corrected versions across all three affected products (Commerce, Commerce B2B, Magento).

Affected
Adobe Commerce
Adobe Commerce B2B
Adobe Magento (Open Source)
Estimated exposure
mass≈100,000–250,000 live storefronts (estimate) — Public web-technology surveys (e.g., BuiltWith/W3Techs) count Magento 2/Adobe Commerce deployments in the hundreds of thousands globally, and a network-reachable core authorization flaw plausibly affects most non-patched deployments; Adobe…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.