Impact
Adobe Commerce, its B2B line, Webhooks Plugin, and the open‑source Magento platform contain an Incorrect Authorization flaw (CWE‑863). The defect enables an attacker to override internal permission checks and read data that should require explicit authorization. No user interaction is needed, but the exploit relies on conditions that the attacker does not directly control, such as the presence of a vulnerable endpoint or specific configuration state.
Affected Systems
The vulnerability affects all releases of Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source that have not been patched following the Adobe security bulletin. No specific version range is provided, so any unpatched copy may be at risk.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of 8% signals a moderate likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation can occur via unsecured or improperly protected APIs or application interfaces, but requires environmental conditions beyond the attacker’s control.
OpenCVE Enrichment