Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass

Vulnerability

A vulnerability allowing security feature bypass through incorrect authorization has been identified in Adobe Commerce. This issue could enable an attacker to gain unauthorized read access by bypassing security measures. The vulnerability affects multiple versions of Adobe Commerce, Magento Open Source, and Adobe Commerce B2B, as well as Adobe Commerce Events. Exploitation of this vulnerability does not require user interaction, but depends on conditions beyond the attacker's control.

Impact

Exploitation of this vulnerability could lead to unauthorized read access by bypassing security measures.

Remediation

Users are advised to update to the latest versions of Adobe Commerce, Magento Open Source, or Adobe Commerce B2B. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73. For Adobe Commerce Events, refer to the guide on upgrading modules and extensions.

Added: Jul 15, 2026, 5:33 AM
Updated: Jul 15, 2026, 5:33 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.3
exploitability
7.6
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.