ZeroHour

CVE-2026-77774

mass

Incorrect Authorization in Adobe Commerce and Magento Enables Security Bypass

CVSS 3.1
8.6 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-77774 is an incorrect authorization flaw (CWE-863) in Adobe Commerce, Adobe Commerce B2B, and Magento that lets an attacker bypass security features and gain unauthorized read access to protected information. The flaw is reachable over the network without credentials or user interaction (CVSS 3.1 8.6: AV:N/AC:L/PR:N/UI:N), and the changed scope indicates the vulnerable component crosses a trust boundary to affect resources outside its own security scope. A successful attacker gains unauthorized access to potentially confidential store data, while integrity and availability are not directly impacted (C:H/I:N/A:N). Any organization running Adobe Commerce, Adobe Commerce B2B, or Magento (including B2B deployments) on vulnerable versions is potentially affected. Exploitation has not been observed: there is no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a ~0.5% probability of exploitation within 30 days.

What to do: Upgrade Adobe Commerce, Adobe Commerce B2B, and Magento installations to the patched release specified in Adobe's security bulletin for CVE-2026-77774, prioritizing internet-facing storefronts. Check that restricted resources (admin areas, APIs, and customer data) enforce authorization correctly and return data only to properly authenticated, authorized users. Monitor Adobe's advisory for exact affected version ranges and any interim mitigations until the fix is deployed.

Affected
Adobe Commerce
Adobe Commerce B2B
Adobe Magento (Magento Open Source)
Estimated exposure
masson the order of 100,000–300,000 live storefronts running Magento/Adobe Commerce worldwide (public usage surveys) — Public web-technology and market-share surveys consistently place the combined Magento/Adobe Commerce installed base in the hundreds of thousands of live e-commerce stores, though only deployments reachable by unauthenticated attackers are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.