Junglewise Threat Intelligence

CVE-2026-77774: Adobe Commerce authorization bypass in security features

CVE-2026-77774 · Severity: high · CVSS 8.6 · Published 2026-09-08

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used by retailers to manage online stores, contains an authorization flaw that allows attackers to bypass security controls and read unauthorized data. This vulnerability requires no user interaction and could enable attackers to access sensitive customer or business information without proper credentials.

Technical details

The vulnerability is an incorrect authorization flaw in Adobe Commerce that allows security feature bypass through unauthorized read access. The attack vector is network-based and requires no user interaction; an attacker can exploit this remotely by making crafted requests that circumvent authorization checks. The scope is changed, meaning an attacker can access resources beyond their normal privilege level. Patch availability and specific affected versions are not detailed in the available advisory content.

Affected products

  • Adobe Commerce

Timeline

  • 2026-09-08: disclosed

References

Related threats