Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Published: 2026-08-11
Score: 9.1 Critical
EPSS: 25.1% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by an Incorrect Authorization flaw that can allow an attacker to gain elevated access to sensitive resources. The vulnerability enables the exploitation of privileged functionality without requiring user interaction, which can lead to unauthorized data disclosure, modification, or further system compromise. The weakness is identified as CWE-863, indicating improper handling of role‑based access controls during authorization checks.

Affected Systems

Affected vendors are Adobe, with products Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version numbers are listed in the available CNA data, so it is unknown which releases contain the flaw. Admins should consult the Adobe advisories for precise version coverage before applying updates.

Risk and Exploitability

The CVSS score of 9.1 marks this as a critical vulnerability, and the EPSS score of 25% indicates a higher probability of widespread exploitation at this time. The flaw is not listed in the CISA KEV catalog, suggesting it is not yet a known widely‑used exploit. Attackers can potentially trigger the flaw without user interaction, likely by sending crafted requests from an authenticated session to resources that lack proper authorization checks. Because of the high severity, retailers with large data assets should prioritize patching or mitigating this vulnerability.

Generated by OpenCVE AI on August 24, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply the vendor‑provided fix for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source as described in the Adobe security advisory.
  • Confirm that all roles have correct permissions by reviewing the role assignment table and removing any unnecessary privileges that allow access to restricted resources.
  • If a patch is not immediately available, restrict HTTP access to the affected API endpoints using a firewall or reverse proxy rules to limit exposure to trusted administrative users only.

Generated by OpenCVE AI on August 24, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Title Adobe Commerce | Incorrect Authorization (CWE-863)
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:34:14.520Z

Reserved: 2026-08-05T23:51:57.377Z

Link: CVE-2026-71362

cve-icon Vulnrichment

Updated: 2026-08-12T13:35:40.712Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T18:18:21.610

Modified: 2026-08-28T00:18:09.390

Link: CVE-2026-71362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses