Impact
Adobe Commerce is affected by an Incorrect Authorization vulnerability that enables a high‑privileged attacker to bypass security controls and access data that should be protected. The flaw does not require user interaction and changes the scope of the vulnerability, allowing the attacker to potentially affect additional components beyond the originally intended target.
Affected Systems
The vulnerability impacts Adobe Commerce and its related components, including Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while an EPSS score of 20% suggests a realistic probability of exploitation soon. Because the flaw can be exploited by an attacker who already has privileged credentials or can elevate privileges within an affected instance, the risk is significant. The vulnerability is not currently listed in CISA’s KEV catalog, but the combination of high severity and nontrivial exploitation likelihood warrants prompt action.
OpenCVE Enrichment