CVE-2026-76202: Adobe Commerce | Incorrect Authorization (CWE-863)
Published Sep 8, 2026
·Updated
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
Affected Software
1 affected component
Adobe Adobe Commerce
Event History
Sep 8, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Can this be exploited remotely without an account or user interaction?
Yes. The vector is network-based, requires low attack complexity, and lists no privileges or user interaction as required.
2
What is the likely impact if exploitation succeeds?
The vulnerability could allow privilege escalation and elevated access to sensitive information. The CVSS vector indicates high confidentiality impact and low integrity impact, with no availability impact.