Impact
Adobe Commerce is affected by an Incorrect Authorization vulnerability that allows an attacker to bypass security controls and retrieve content they should not be able to read. The flaw changes the scope of access rights, meaning that read operations on protected resources can succeed without proper authorization. The impact is the unauthorized disclosure of sensitive data, and the weakness is classified as CWE‑863.
Affected Systems
Affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, the vulnerability impacts all versions of these products unless patched. Specific version details are not provided in the advisory, so users should verify whether their installed instances are affected and apply any available updates from Adobe.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog at this time. Exploitation does not require user interaction and adversely changes the authorization scope, making it relatively easy for an attacker to obtain unauthorized data.
OpenCVE Enrichment