Impact
Adobe Commerce is affected by an Incorrect Authorization flaw that could allow an attacker who already has high privileges to gain further elevated access to restricted resources. The flaw does not require user interaction. The weakness originates from insufficient authorization checks, potentially enabling access to resources reserved for higher privilege levels.
Affected Systems
The affected products are Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version numbers are listed in the CVE data, so all installed variations may remain vulnerable until a vendor patch is applied or the product is upgraded.
Risk and Exploitability
The CVSS base score of 2.7 indicates a low severity. Because the flaw does not require user interaction, it could be triggered automatically by an attacker who already possesses a high‑privilege account. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, so there is no current evidence of widespread exploitation. Nevertheless, organizations using the affected products should patch the vulnerability promptly to mitigate possible privilege escalation.
OpenCVE Enrichment