CVE-2026-76202
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
- CWE
- CWE-863
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- Adobe Adobe Commerce
- Adobe Adobe Commerce
- Adobe Adobe Commerce B2B
- Adobe Adobe Commerce B2B
- Adobe Magento Open Source
- Adobe Magento Open Source
Weakness type
Related vulnerabilities
- CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
- CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
- CVE-2026-86755 — Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
- CVE-2026-86754 — Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
- CVE-2026-86753 — snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
- CVE-2026-86752 — snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
- CVE-2026-86750 — snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
- CVE-2026-86747 — snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User