CVE-2026-77774
massIncorrect Authorization in Adobe Commerce and Magento Enables Security Bypass
CVE-2026-77774 is an incorrect authorization flaw (CWE-863) in Adobe Commerce, Adobe Commerce B2B, and Magento that lets an attacker bypass security features and gain unauthorized read access to protected information. The flaw is reachable over the network without credentials or user interaction (CVSS 3.1 8.6: AV:N/AC:L/PR:N/UI:N), and the changed scope indicates the vulnerable component crosses a trust boundary to affect resources outside its own security scope. A successful attacker gains unauthorized access to potentially confidential store data, while integrity and availability are not directly impacted (C:H/I:N/A:N). Any organization running Adobe Commerce, Adobe Commerce B2B, or Magento (including B2B deployments) on vulnerable versions is potentially affected. Exploitation has not been observed: there is no public proof-of-concept, no CISA KEV listing, and EPSS estimates only a ~0.5% probability of exploitation within 30 days.
What to do: Upgrade Adobe Commerce, Adobe Commerce B2B, and Magento installations to the patched release specified in Adobe's security bulletin for CVE-2026-77774, prioritizing internet-facing storefronts. Check that restricted resources (admin areas, APIs, and customer data) enforce authorization correctly and return data only to properly authenticated, authorized users. Monitor Adobe's advisory for exact affected version ranges and any interim mitigations until the fix is deployed.
| Adobe Commerce | — |
| Adobe Commerce B2B | — |
| Adobe Magento (Magento Open Source) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.