Incorrect Authorization in Adobe Commerce and Magento Open Source
Adobe Commerce and Magento Open Source contain an incorrect authorization flaw enabling privilege escalation to sensitive resources. CVSS 9.1 critical. Actively exploited in wild.
- Vendor
- Adobe
- Product
- Commerce, Magento Open Source
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.5%
- Status
- exploited-in-wild
- Published
An incorrect authorization vulnerability in Adobe Commerce and Magento Open Source allows an attacker to escalate privileges and access sensitive resources without requiring user interaction. Adobe published the CVE on August 11, 2026; confirmed exploitation targeting customer accounts surfaced within 24 hours.
Severity: critical. CVSS 9.1. Exploitation does not require user interaction.
Patch available. No workaround exists — patching is the only remediation. Affected version ranges and update packages: Adobe security bulletins. Full technical record: NVD.
