
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-77111 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows a security feature bypass. An attacker with high privileges can exploit this flaw to bypass security measures and gain unauthorized write access, with a changed scope affecting integrity and availability. Affected versions include Adobe Commerce 2.4.4 through 2.4.9 (August 2026 releases), Commerce B2B 1.3.3 through 1.5.3 (August 2026 releases), and Magento Open Source 2.4.6 through 2.4.9 (August 2026 releases). The vulnerability was published on September 8, 2026, with a patch made available the following day. It carries a CVSS v3.1 base score of 8.7 (High) (Adobe Advisory).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to properly verify that an authenticated high-privileged user is authorized to perform certain write operations, allowing those controls to be bypassed. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require an attacker to already possess high-privilege credentials. The changed scope indicates that the impact extends beyond the vulnerable component itself to other system components. No public technical write-ups or proof-of-concept code have been identified at this time (Adobe Advisory).
Successful exploitation allows an authenticated high-privileged attacker to bypass security controls and gain unauthorized write access to system components, resulting in high integrity and high availability impact across a changed scope. Confidentiality is not directly impacted by this vulnerability. The changed scope means that exploitation could affect components or data stores beyond the immediate Adobe Commerce application, potentially enabling modification of critical configuration, catalog data, or order data, and causing service disruption (Adobe Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to already hold high-privilege credentials within the Adobe Commerce environment, which significantly limits the attack surface (Adobe Advisory).
Adobe has released security patches addressing this vulnerability as part of the September 2026 security update (APSB26-138). Administrators should upgrade to the September 2026 patch releases for their respective product lines: Adobe Commerce 2.4.4-2026-sep through 2.4.9-2026-sep, Commerce B2B 1.3.3-2026-sep through 1.5.3-2026-sep, and Magento Open Source 2.4.7-2026-sep through 2.4.9-2026-sep. As interim measures, organizations should review and restrict high-privilege account assignments to only necessary users and monitor for unauthorized write operations on critical system components (Adobe Advisory).
The vulnerability was noted by CIS Security in an advisory covering multiple Adobe product vulnerabilities patched in September 2026, flagging the potential for arbitrary code execution across the Adobe product suite. AUSCERT also published a bulletin (ESB-2026.10690) and INCIBE-CERT issued an early warning alert for this CVE. Coverage has been limited to standard vulnerability aggregation and advisory channels, with no notable independent researcher commentary or significant social media discussion identified (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."