CVE-2026-77774: Adobe Commerce | Incorrect Authorization (CWE-863)
Published Sep 8, 2026
·Updated
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
1 affected component
Adobe Adobe Commerce
Event History
Sep 8, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No privileges or user interaction are required. The network attack vector indicates the issue can be exploited remotely.
2
What is the likely impact if exploitation succeeds?
An attacker could bypass security measures and obtain unauthorized read access. The vulnerability affects confidentiality, while the supplied vector does not indicate integrity or availability impact.