Junglewise Threat Intelligence

CVE-2026-77109: Adobe Commerce privilege escalation via incorrect authorization

CVE-2026-77109 · Severity: high · CVSS 8.6 · Published 2026-09-08

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a widely-used e-commerce platform for online stores, contains an authorization flaw that allows attackers to bypass access controls and escalate their privileges. An attacker can exploit this vulnerability without user interaction to gain elevated access to sensitive resources and administrative functions, potentially leading to unauthorized modification of store data, customer information, or business-critical operations.

Technical details

This is a privilege escalation vulnerability caused by incorrect authorization checks in Adobe Commerce. The vulnerability allows an attacker with network access to bypass authentication or authorization mechanisms and gain elevated privileges on the platform. No user interaction is required for exploitation, and the vulnerability changes the scope of impact. The attack vector is network-based, enabling remote exploitation to access restricted resources and administrative functionality.

Affected products

  • Adobe Commerce

Timeline

  • 2026-09-08: disclosed

References

Related threats