Impact
Adobe Commerce, including Adobe Commerce B2B and Magento Open Source, has an Incorrect Authorization flaw that allows an attacker to bypass access controls and assume higher privileges. The vulnerability can expose sensitive data and grant the attacker the ability to execute actions reserved for authenticated administrators, thereby compromising confidentiality and integrity of the system.
Affected Systems
The affected products are Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version information is provided, so the vulnerability may apply broadly across released editions until the vendor releases a fix.
Risk and Exploitability
The flaw is a high‑severity issue with a CVSS score of 8.2. The vendor’s advisory indicates that exploitation does not require user interaction, implying a remote attack vector where a malicious actor can trigger the flaw through the application’s interfaces or APIs. The EPSS score of 0.4% demonstrates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and lack of interaction requirements warrant immediate attention.
OpenCVE Enrichment