Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce is affected by an Incorrect Authorization flaw that could allow an attacker who already has high privileges to gain further elevated access to restricted resources. The flaw does not require user interaction. The weakness originates from insufficient authorization checks, potentially enabling access to resources reserved for higher privilege levels.

Affected Systems

The affected products are Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version numbers are listed in the CVE data, so all installed variations may remain vulnerable until a vendor patch is applied or the product is upgraded.

Risk and Exploitability

The CVSS base score of 2.7 indicates a low severity. Because the flaw does not require user interaction, it could be triggered automatically by an attacker who already possesses a high‑privilege account. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of widespread exploitation. Nevertheless, organizations using the affected products should patch the vulnerability promptly to mitigate possible privilege escalation.

Generated by OpenCVE AI on August 12, 2026 at 13:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe patch or upgrade to a fixed version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source.
  • Limit the number of accounts with high‑privilege roles and enforce the principle of least privilege for all users.
  • Configure and audit role‑based access controls to ensure that lower‑privileged users cannot access resources reserved for higher roles.

Generated by OpenCVE AI on August 12, 2026 at 13:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.
Title Adobe Commerce | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:56.944Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48412

cve-icon Vulnrichment

Updated: 2026-08-11T18:54:14.047Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T18:17:30.960

Modified: 2026-08-28T00:17:58.577

Link: CVE-2026-48412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T03:15:11Z

Weaknesses