CVE-2026-77108: Adobe Commerce | Incorrect Authorization (CWE-863)
Published Sep 8, 2026
·Updated
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
Affected Software
1 affected component
Adobe Commerce
Event History
Sep 8, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The vulnerability has no authentication requirement (PR:N), so an unauthenticated attacker can attempt exploitation over the network. No user interaction is required.
2
What is the likely impact if exploitation succeeds?
Successful exploitation could allow privilege escalation and elevated access to sensitive information. The provided impact metrics indicate high confidentiality impact, with no stated integrity or availability impact.