Impact
Adobe Commerce suffers from an incorrect authorization flaw that allows a user with elevated privileges to bypass protective measures and gain write access to protected resources. This weakness, identified as CWE-863, enables the attacker to modify or create data that should be restricted, potentially compromising data integrity and availability.
Affected Systems
Affected vendors include Adobe:Adobe Commerce, Adobe:Adobe Commerce B2B, and Adobe:Magento Open Source. No specific version numbers are listed in the advisory, so all current releases may be at risk until a vendor update is applied.
Risk and Exploitability
The Vulnerability has a CVSS score of 6.5, indicating moderate severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild. It is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a compromised or privileged account executing privileged operations within the application, and does not require any user interaction to be triggered.
OpenCVE Enrichment