Impact
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by an Incorrect Authorization flaw that can allow an attacker to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction and results in privilege escalation.
Affected Systems
Adobe products Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are impacted. The vulnerability covers Adobe Commerce releases 2.4.4 through 2.4.9, Adobe Commerce B2B releases 1.3.3 through 1.5.3, and Magento Open Source releases 2.4.7 through 2.4.9. Admins should verify their specific version numbers against the advisory before applying updates.
Risk and Exploitability
The CVSS score of 9.1 marks this as a critical vulnerability, and the EPSS score of 88% indicates a high probability of exploitation. It is listed in the CISA KEV catalog. Attackers can potentially trigger the flaw without user interaction, likely by sending crafted requests from an authenticated session to resources that lack proper authorization checks.
OpenCVE Enrichment