Back

CRITICAL KEV

Adobe Commerce | Incorrect Authorization (CWE-863)

Published Aug 11, 2026 ·Due Sep 27, 2026

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (7)
  1. CISA ADP
    • SSVC exploitation changed from none to active
  2. CISA ADP
    • SSVC exploitation changed from active to none
  3. CISA ADP
    • SSVC exploitation changed from none to active
  4. CISA ADP
    • SSVC exploitation changed from active to none
  5. CISA ADP
    • SSVC exploitation changed from none to active
  6. CISA ADP
    • SSVC exploitation changed from active to none
  7. CISA ADP
    • SSVC exploitation changed from none to active
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Aug 11, 2026
Updated Sep 25, 2026
Reserved Aug 5, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Analyzed
Modified Sep 15, 2026
Red Hat
Severity n/a
Public date n/a