Junglewise Threat Intelligence

CVE-2026-77108: Adobe Commerce incorrect authorization privilege escalation

CVE-2026-77108 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a widely-used e-commerce platform for managing online stores, contains an authorization vulnerability that allows attackers to gain elevated privileges and access sensitive information. No user interaction is required for exploitation, meaning an attacker can launch an attack directly against a vulnerable system over the network.

Technical details

The vulnerability is an Incorrect Authorization flaw in Adobe Commerce that enables privilege escalation. The vulnerability is network-accessible and does not require user interaction, indicating an unauthenticated or low-privilege attack vector. An attacker can exploit this issue to bypass access controls and gain elevated permissions, potentially accessing sensitive customer data, order information, or administrative functions. Patch availability should be confirmed through Adobe's official security advisory.

Affected products

  • Adobe Commerce

Timeline

  • 2026-09-08: disclosed

References

Related threats