
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77109 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows unauthenticated remote attackers to escalate privileges and gain elevated access to restricted resources. The vulnerability was published on September 8, 2026, and affects Adobe Commerce versions through the August 2026 patch cycle (2.4.4 through 2.4.9), Adobe Commerce B2B versions 1.3.3 through 1.5.3, and Magento Open Source versions through 2.4.9. Exploitation does not require user interaction, and the scope is changed, meaning the impact extends beyond the vulnerable component. It carries a CVSS v3.1 base score of 8.6 (High) (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to correctly verify whether a requesting party has the appropriate permissions to access a resource or perform an action. An unauthenticated attacker can send crafted network requests to exploit this flaw, bypassing authorization checks and gaining elevated access to restricted resources without any user interaction. The changed scope indicator in the CVSS vector (S:C) suggests that the impact can extend to components or data beyond the directly vulnerable application context, amplifying the potential damage. No specific technical write-ups or public proof-of-concept code have been identified at this time (Feedly).
Successful exploitation allows an unauthenticated network attacker to escalate privileges and gain unauthorized access to restricted resources within Adobe Commerce, Adobe Commerce B2B, and Magento Open Source instances. The primary impact is on integrity (rated High), as attackers can modify data or perform unauthorized actions across affected systems; confidentiality and availability are not directly impacted per the CVSS scoring. Given the changed scope, exploitation could affect data or functionality beyond the immediate application, potentially enabling unauthorized administrative actions, manipulation of orders or customer data, or access to sensitive B2B configurations (Feedly).
As of the time of disclosure, there is no evidence of active in-the-wild exploitation or publicly available proof-of-concept exploit code for CVE-2026-77109. The vulnerability is automatable (per SSVC assessment) and requires no authentication or user interaction, making it attractive for opportunistic attackers if a PoC becomes available. The EPSS score is approximately 0.0041 (0.41%), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (Feedly).
Adobe has released security patches addressing CVE-2026-77109 as part of the September 2026 patch cycle (APSB26-138). Administrators should update to the September 2026 releases for their respective product lines: Adobe Commerce 2.4.4-2026-sep, 2.4.5-2026-sep, 2.4.6-2026-sep, 2.4.7-2026-sep, 2.4.8-2026-sep, or 2.4.9-2026-sep; Adobe Commerce B2B 1.3.3-2026-sep, 1.3.4-2026-sep, 1.4.2-2026-sep, 1.5.2-2026-sep, or 1.5.3-2026-sep; and Magento Open Source 2.4.7-2026-sep, 2.4.8-2026-sep, or 2.4.9-2026-sep. As an interim measure, administrators should implement network segmentation to restrict access to administrative interfaces and review access logs for any unauthorized privilege escalation attempts (Adobe Advisory).
The vulnerability was noted by CIS (Center for Internet Security) in an advisory covering multiple Adobe product vulnerabilities in September 2026, and was picked up by several threat intelligence aggregators including AusCERT, INCIBE-CERT, and BeyondMachines shortly after disclosure. No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking and advisory republication (CIS Advisory, AusCERT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."