Impact
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and all earlier releases are affected by an Incorrect Authorization vulnerability (CWE-863). The flaw allows a low‑privileged attacker to bypass security controls and view data that should be restricted, without requiring any user interaction. The impact is therefore a limited unauthorized view access to sensitive data.
Affected Systems
Affected systems are Adobe Commerce installations matching the listed CPE strings, including community, B2B, and open‑source Magento releases up to the specified patch levels. All vendors listed under the CNA (Adobe:Adobe Commerce) are impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate risk when considering existing access controls. EPSS is below 1%, suggesting few current exploits. It is not present in CISA’s KEV catalog. Attackers can likely exploit the vulnerability remotely from a web client, as no user interaction is required according to the vendor advisory.
OpenCVE Enrichment