Incorrect Authorization Vulnerability in Adobe Commerce
CVE-2026-77111

8.7HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
8 September 2026

What is CVE-2026-77111?

Adobe Commerce is susceptible to an Incorrect Authorization vulnerability that enables an attacker with elevated privileges to bypass implemented security measures. This could lead to unauthorized write access to the system, posing a risk to the integrity of stored data. Notably, the exploitation of this vulnerability does not necessitate any user interaction, making it a significant concern for organizations utilizing the platform. The issue requires prompt attention to mitigate potential impacts on system availability.

Affected Version(s)

Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug

Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug

Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.