Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9
- <= 2.4.8-p5
- <= 2.4.7-p10
- <= 2.4.6-p15
- <= 2.4.5-p17
- <= 2.4.4-p18
A vulnerability has been identified in Adobe Commerce that involves incorrect authorization, potentially allowing a high-privileged attacker to bypass security measures and gain unauthorized read access. This vulnerability affects several versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Notably, exploitation does not require user interaction.
Exploitation of this vulnerability could lead to unauthorized read access by bypassing security features.
Users are advised to update to the latest versions of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.