Impact
Adobe Commerce is affected by an Incorrect Authorization flaw that enables an attacker to bypass security measures and gain unauthorized read and limited write access to protected resources. The vulnerability neglects proper authorization checks, allowing malicious actors to read sensitive data and perform restricted modifications without needing user interaction. This weakness, classified as CWE‑863, effectively undermines the confidentiality and integrity controls of the platform.
Affected Systems
All installations of Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source are impacted. Version information is not provided in the advisory, so any version released before an official patch should be considered vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.2, classifying it as high severity, and an EPSS score of less than 1%, indicating that exploitation is currently unlikely. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker can exploit the vulnerability remotely via exposed API endpoints, without requiring user interaction.
OpenCVE Enrichment