---
id: CVE-2026-77108
title: >-
  Adobe Commerce is affected by an Incorrect Authorization vulnerability that
  could result in privilege escalation
summary: >-
  Adobe Commerce is affected by an Incorrect Authorization vulnerability that
  could result in privilege escalation. An attacker could leverage this
  vulnerability to gain elevated access to sensitive information. Exploitation
  of this issue …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: adobe
product: commerce
affected:
  - commerce < 2.4.4
  - commerce = 2.4.4
  - commerce = 2.4.5
  - commerce = 2.4.6
  - commerce = 2.4.7
  - commerce = 2.4.8
  - commerce = 2.4.9
  - commerce_b2b < 1.3.3
  - commerce_b2b = 1.3.3
  - commerce_b2b = 1.3.4
  - commerce_b2b = 1.4.2
  - commerce_b2b = 1.5.2
  - commerce_b2b = 1.5.3
  - magento <= 2.4.6
  - magento = 2.4.7
  - magento = 2.4.8
  - magento = 2.4.9
patched:
  - commerce 2.4.4
  - commerce_b2b 1.3.3
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T21:17:15.790'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77108'
references:
  - url: 'https://helpx.adobe.com/security/products/magento/apsb26-138.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-11T20:53:51.107020Z'
epss: 0.00479
epssPercentile: 0.40342
ingestedAt: '2026-09-08T19:08:49.640Z'
---

## Overview

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

## Affected

- `commerce < 2.4.4`
- `commerce = 2.4.4`
- `commerce = 2.4.5`
- `commerce = 2.4.6`
- `commerce = 2.4.7`
- `commerce = 2.4.8`
- `commerce = 2.4.9`
- `commerce_b2b < 1.3.3`
- `commerce_b2b = 1.3.3`
- `commerce_b2b = 1.3.4`
- `commerce_b2b = 1.4.2`
- `commerce_b2b = 1.5.2`
- `commerce_b2b = 1.5.3`
- `magento <= 2.4.6`
- `magento = 2.4.7`
- `magento = 2.4.8`
- `magento = 2.4.9`

## Remediation

Upgrade past the affected range:

- `commerce 2.4.4`
- `commerce_b2b 1.3.3`
