CVE-2026-77109
massIncorrect Authorization Privilege Escalation in Adobe Commerce / Magento
Adobe Commerce, Adobe Commerce B2B, and Magento are affected by an incorrect authorization flaw (CWE-863) in the platform's access-control handling. Because the vector requires no prior privileges and no user interaction, a remote, unauthenticated attacker can trigger the issue directly over the network. Successful exploitation allows the attacker to gain elevated access to resources that should be restricted, resulting in a high-impact integrity compromise (the scope-change flag indicates a second authority boundary, such as the application vs. its data or admin scope, is affected). Any organization running the affected versions of these e-commerce platforms is exposed, with storefronts handling customer and order data the primary concern. There is currently no known public proof-of-concept, no listing in CISA's KEV catalog, and only a modest 0.4% 30-day exploitation probability (EPSS), so exploitation in the wild is not yet confirmed.
What to do: Patch by upgrading to the fixed release listed in Adobe's security bulletin for this CVE, since the source data does not specify exact version numbers; prioritize internet-exposed admin and API surfaces. Until patched, restrict network access to administrative and API endpoints and review logs for unexpected privilege changes or access to restricted resources. Track Adobe's bulletin for corrected versions across all three affected products (Commerce, Commerce B2B, Magento).
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| Adobe Magento (Open Source) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.