Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Published: 2026-07-14
Score: 5.9 Medium
EPSS: 9.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce, its B2B line, Webhooks Plugin, and the open‑source Magento platform contain an Incorrect Authorization flaw (CWE‑863). The defect enables an attacker to override internal permission checks and read data that should require explicit authorization. No user interaction is needed, but the exploit relies on conditions that the attacker does not directly control, such as the presence of a vulnerable endpoint or specific configuration state.

Affected Systems

The vulnerability affects all releases of Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source that have not been patched following the Adobe security bulletin. No specific version range is provided, so any unpatched copy may be at risk.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score of 8% signals a moderate likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation can occur via unsecured or improperly protected APIs or application interfaces, but requires environmental conditions beyond the attacker’s control.

Generated by OpenCVE AI on August 3, 2026 at 03:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update Adobe Commerce to the latest release as specified in the Adobe security bulletin.
  • Enable detailed logging for authorization checks and monitor the logs for anomalous read access attempts.
  • Review and enforce role‑based permissions on all API endpoints and administrative interfaces to restrict unauthorized read operations.
  • Validate any custom modules or third‑party plugins for improper authorization logic and apply fixes or restrictions as needed.

Generated by OpenCVE AI on August 3, 2026 at 03:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Title Adobe Commerce | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Adobe Commerce Webhooks Plugin Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-15T15:12:20.602Z

Reserved: 2026-05-20T15:50:31.367Z

Link: CVE-2026-47997

cve-icon Vulnrichment

Updated: 2026-07-15T13:53:29.222Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:53:00Z

Weaknesses