Junglewise Threat Intelligence

CVE-2026-77111: Adobe Commerce incorrect authorization in security feature

CVE-2026-77111 · Severity: high · CVSS 8.7 · Published 2026-09-08

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a widely-used e-commerce platform, contains an authorization flaw that allows privileged attackers to bypass security controls and gain unauthorized write access to the system. This could enable an attacker with high-level privileges to make unauthorized changes that disrupt service availability or compromise data integrity.

Technical details

This is an Incorrect Authorization (CWE-863) vulnerability in Adobe Commerce that allows a privileged attacker to bypass security features. The vulnerability requires the attacker to already possess high privileges; no user interaction is required for exploitation. The attack vector is network-based, and successful exploitation results in unauthorized write access to the system, changing the security scope and causing limited disruption to availability. No patch information is currently available from the provided advisory.

Affected products

  • Adobe Commerce

Timeline

  • 2026-09-08: disclosed

References

Related threats