Impact
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are vulnerable to an Incorrect Authorization flaw identified as CWE‑863. An attacker who exploits this flaw can elevate their privileges and gain unauthorized access to sensitive data without requiring any user interaction, thereby potentially compromising the confidentiality and integrity of the affected installations.
Affected Systems
The affected products are Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. No specific version range is indicated by the CNA, so all released versions of these products remain at risk until a fix is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score is not available, making exploit likelihood uncertain. The vulnerability is not yet listed in the CISA KEV catalog, implying no confirmed live exploitation at reporting time. Based on the description, it is inferred that the likely attack vector involves remote exploitation of the administrative interface, and a remote attacker could gain elevated rights from any network‑connected environment after initial compromise or from another vulnerable endpoint.
OpenCVE Enrichment