CVE-2026-77109

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.

  • Published Sep 8, 2026
  • CVSS 8.6 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-77109 at the National Vulnerability Database