Impact
Adobe Commerce, including its B2B extension, the Webhooks Plugin, and Magento Open Source, are affected by an incorrect authorization flaw that allows an attacker to bypass security controls without any user interaction. The vulnerability enables unauthorized read and write access to protected resources, exposing sensitive data and permitting unauthorized modification, as indicated by CWE‑863.
Affected Systems
All installations of Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source are impacted. Version information is not provided in the advisory, so any version released before an official patch should be considered vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.2, classifying it as high severity, and an EPSS score of less than 1%, indicating that exploitation is currently unlikely. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit the vulnerability remotely via exposed API endpoints, without requiring user interaction.
OpenCVE Enrichment