Impact
This vulnerability is an Incorrect Authorization flaw that permits attackers to gain unauthorized elevated privileges within Adobe Commerce, including its B2B and Magento Open Source variants. The flaw can change the scope, enabling access to resources that are normally restricted to higher‑level users, potentially compromising data integrity and allowing further system compromise.
Affected Systems
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected. No specific version range is listed, so any implementation lacking the latest security updates may be vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, the EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog. Exploitation does not require user interaction and can be triggered by specially crafted requests that bypass normal authorization checks, changing the scope and allowing access to resources normally restricted to higher‑level users.
OpenCVE Enrichment