CVE-2026-77111
largeIncorrect Authorization in Adobe Commerce and Magento Enables Privileged Write Bypass
Adobe Commerce, its B2B module, and Magento contain an incorrect authorization flaw (CWE-863) in which the security check is applied incorrectly, allowing security measures to be bypassed. The flaw is reachable over the network and requires no user interaction, but the attacker must already hold high privileges, such as an admin-level account or privileged integration. A successful exploit yields unauthorized write access (high integrity impact) with possible limited availability impact, and the 'scope changed' rating means the bypass can affect security boundaries beyond the vulnerable component itself. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is potentially affected. There is currently no known exploitation: the flaw is absent from CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.5% (42nd percentile) chance of exploitation within 30 days.
What to do: Check Adobe's security bulletin for this CVE to identify affected and fixed versions, and upgrade Adobe Commerce, Adobe Commerce B2B, and Magento to the patched release once published. Until then, audit and restrict high-privilege admin and API integration credentials, since exploitation requires an attacker who already holds high privileges, and monitor write activity and admin logs for unexpected changes. Given the 'scope changed' rating, also review cross-scope permissions to confirm the bypass cannot reach adjacent security boundaries.
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| Adobe Magento | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.