Impact
Adobe Commerce suffers from an incorrect authorization flaw that allows a malicious actor to bypass security controls and gain read access to protected data. The vulnerability is identified as CWE-863 and does not require user interaction to be exploited. Attackers can potentially obtain sensitive information without triggering user prompts.
Affected Systems
The affected products include Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. Version specifics are not disclosed, so any deployed instance of these products should be considered at risk until a patch is available.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of real-world exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation does not require user interaction and relies on conditions external to the attacker’s control. It is reasonable to infer that the attack could be carried out remotely via the web interface or API, potentially enabling unauthorized data retrieval if proper authorization checks fail.
OpenCVE Enrichment