Impact
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by an Incorrect Authorization flaw that can allow an attacker to gain elevated access to sensitive resources. The vulnerability enables the exploitation of privileged functionality without requiring user interaction, which can lead to unauthorized data disclosure, modification, or further system compromise. The weakness is identified as CWE-863, indicating improper handling of role‑based access controls during authorization checks.
Affected Systems
Affected vendors are Adobe, with products Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version numbers are listed in the available CNA data, so it is unknown which releases contain the flaw. Admins should consult the Adobe advisories for precise version coverage before applying updates.
Risk and Exploitability
The CVSS score of 9.1 marks this as a critical vulnerability, and the EPSS score of 25% indicates a higher probability of widespread exploitation at this time. The flaw is not listed in the CISA KEV catalog, suggesting it is not yet a known widely‑used exploit. Attackers can potentially trigger the flaw without user interaction, likely by sending crafted requests from an authenticated session to resources that lack proper authorization checks. Because of the high severity, retailers with large data assets should prioritize patching or mitigating this vulnerability.
OpenCVE Enrichment