Impact
The vulnerability is an Incorrect Authorization flaw (CWE-863) that allows an attacker to bypass security controls and read or modify data within Adobe Commerce, its B2B component, the Webhooks Plugin, or Magento Open Source. An attacker who successfully leverages the flaw can obtain unauthorized read and write permissions without any user interaction, potentially exposing or altering sensitive information.
Affected Systems
Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, Magento Open Source. No specific affected version numbers are disclosed in the CVE data, so all current releases may be vulnerable until a patch becomes available.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% shows a low estimated probability of exploitation as of this analysis. The vulnerability is not listed in the CISA KEV catalog. Because the description states that exploitation does not require user interaction, the likely attack vector is remote, possibly through crafted requests to the affected components, though the exact method is not detailed in the CVE.
OpenCVE Enrichment