Impact
Adobe Commerce is affected by an incorrect authorization flaw (CWE‑863) that lets a low‑privileged attacker bypass security checks. The vulnerability can be exploited without user interaction and, if successful, grants the attacker unauthorized read and write privileges, potentially causing limited disruption to service availability.
Affected Systems
The vulnerability impacts Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific product versions are listed, so all current releases are potentially affected unless a vendor release notes the fix.
Risk and Exploitability
The CVSS score of 7.6 indicates a high‑severity exploitation scenario, while the EPSS score (< 1 %) suggests a low likelihood of widespread attacks. The issue is not listed in CISA KEV. Because no user interaction is required and the flaw involves inadequate authorization checks, the likely attack vector is a remote API call or internal request that bypasses normal access controls.
OpenCVE Enrichment