Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass

Vulnerability

A vulnerability allowing security feature bypass through incorrect authorization has been identified in Adobe Commerce. This issue could enable an attacker to gain unauthorized read and write access. The vulnerability is present in multiple versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, as well as in Adobe Commerce Events versions 1.6.0 to 1.20.0. Exploitation of this vulnerability does not require user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized read and write access, allowing attackers to bypass security measures and potentially manipulate data or application behavior.

Remediation

Users are advised to update to the latest versions of Adobe Commerce, Adobe Commerce B2B, Magento Open Source, or Adobe Commerce Events. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.

Added: Jul 15, 2026, 5:36 AM
Updated: Jul 15, 2026, 5:36 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
7.6
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.