
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77108 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce, Magento Open Source, and Adobe Commerce B2B that allows unauthenticated remote attackers to escalate privileges and gain elevated access to sensitive information. The vulnerability was published on September 8, 2026, and affects Adobe Commerce versions 2.4.4 through 2.4.9 (August 2026 patch levels), Magento Open Source versions 2.4.6 through 2.4.9 (August 2026 patch levels), and Adobe Commerce B2B versions 1.3.3 through 1.5.3 (August 2026 patch levels). It carries a CVSS v3.1 base score of 7.5 (High), with no user interaction required for exploitation (Adobe Advisory).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to properly verify that a requesting party has the appropriate permissions before granting access to a resource or functionality. The attack vector is network-based, requires no authentication, no privileges, and no user interaction, making it exploitable remotely by any unauthenticated attacker. The flaw enables privilege escalation, allowing an attacker to bypass authorization controls and access sensitive information that should be restricted to higher-privileged roles. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation allows an unauthenticated network attacker to escalate privileges within Adobe Commerce or Magento Open Source and gain unauthorized access to sensitive information, resulting in a high confidentiality impact. Integrity and availability are not directly affected by this vulnerability. Given the e-commerce context of the affected platforms, exposed sensitive data could include customer personally identifiable information (PII), order details, payment-related data, or administrative configurations, potentially enabling further attacks or regulatory compliance violations (Adobe Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Adobe Advisory). The EPSS score is approximately 0.479%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Adobe has released patched versions addressing this vulnerability as part of the September 2026 security update (APSB26-138). Affected users should upgrade to the September 2026 patch releases: Adobe Commerce 2.4.4-2026-sep, 2.4.5-2026-sep, 2.4.6-2026-sep, 2.4.7-2026-sep, 2.4.8-2026-sep, or 2.4.9-2026-sep; Magento Open Source 2.4.7-2026-sep, 2.4.8-2026-sep, or 2.4.9-2026-sep; and Adobe Commerce B2B 1.3.3-2026-sep, 1.3.4-2026-sep, 1.4.2-2026-sep, 1.5.2-2026-sep, or 1.5.3-2026-sep. As an interim measure while patches are being deployed, administrators should monitor access logs for suspicious privilege escalation attempts and consider implementing network-based access controls to limit exposure of the Commerce admin and API endpoints (Adobe Advisory).
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Adobe products, including this one, could allow for arbitrary code execution and privilege escalation, recommending prompt patching (CIS Advisory). AUSCERT and INCIBE also published bulletins alerting their respective communities to the vulnerability. No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."