CVE-2026-77111

high

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

References

https://helpx.adobe.com/security/products/magento/apsb26-138.html

Details

Source: Mitre, NVD

Published: 2026-09-08

Updated: 2026-09-11

Risk Information

CVSS v2

Base Score: 7.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.7

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.00509