AdobeCVE-2026-77109
Adobe Commerce: improper authorization
High8.6CVE-2026-77109 · Published Sep 8, 2026 · updated Sep 9, 2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Adobe Commerce Product | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-a | No fix yet |
| Adobe Commerce B2B Product | <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-a | No fix yet |
| Magento Open Source Product | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-a | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Adobe advisories
All Adobe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Adobe Acrobat 2024: heap buffer overflow | Medium5.5 | No fix yet |
| Sep 8 | Adobe Acrobat 2024: prototype pollution | High8.2 | No fix yet |
| Sep 8 | Adobe Acrobat 2024: improper authorization | High8.8 | No fix yet |
| Sep 8 | Adobe Acrobat 2024: improper authorization | Medium6.3 | No fix yet |
| Sep 8 | Adobe Acrobat 2024: resource exhaustion | Medium5.5 | No fix yet |
| Sep 8 | Adobe Acrobat 2024: use after free | High7.8 | No fix yet |