ZeroHour

CVE-2026-77111

large

Incorrect Authorization in Adobe Commerce and Magento Enables Privileged Write Bypass

CVSS 3.1
8.7 high
EPSS
<1%p40
Published
()
Modified
AI analysis

Adobe Commerce, its B2B module, and Magento contain an incorrect authorization flaw (CWE-863) in which the security check is applied incorrectly, allowing security measures to be bypassed. The flaw is reachable over the network and requires no user interaction, but the attacker must already hold high privileges, such as an admin-level account or privileged integration. A successful exploit yields unauthorized write access (high integrity impact) with possible limited availability impact, and the 'scope changed' rating means the bypass can affect security boundaries beyond the vulnerable component itself. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is potentially affected. There is currently no known exploitation: the flaw is absent from CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% (42nd percentile) chance of exploitation within 30 days.

What to do: Check Adobe's security bulletin for this CVE to identify affected and fixed versions, and upgrade Adobe Commerce, Adobe Commerce B2B, and Magento to the patched release once published. Until then, audit and restrict high-privilege admin and API integration credentials, since exploitation requires an attacker who already holds high privileges, and monitor write activity and admin logs for unexpected changes. Given the 'scope changed' rating, also review cross-scope permissions to confirm the bypass cannot reach adjacent security boundaries.

Affected
Adobe Commerce
Adobe Commerce B2B
Adobe Magento
Estimated exposure
largeon the order of 150,000–300,000 Magento/Adobe Commerce storefronts worldwide — Public web-technology surveys (e.g., BuiltWith) attribute roughly 150k–300k live sites to Magento/Adobe Commerce, which are typically deployed as self-hosted or cloud-hosted storefronts with a network-reachable admin panel, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.