Unauthorized Access Risk in Adobe Commerce Product
CVE-2026-77774
8.6HIGH
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-77774?
Adobe Commerce has a vulnerability allowing an incorrect authorization flaw that can enable attackers to circumvent security measures and gain unauthorized read access. This vulnerability requires no user interaction, making it particularly concerning for users. Proper security practices and timely patching are essential to mitigate risks associated with this issue.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug