Incorrect Authorization Vulnerability in Adobe Commerce
CVE-2026-76202
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-76202?
Adobe Commerce is impacted by an Incorrect Authorization vulnerability that allows attackers to escalate privileges without requiring user interaction. By exploiting this flaw, malicious actors may gain unauthorized access to sensitive information, posing a significant risk to both user data and the integrity of the system. It is essential for users to implement security measures and stay updated with patches to mitigate potential threats.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug