Intel

AIKIDO-2026-183897

magento/extension-b2b is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-71362 Published 4 days ago

91

Critical Risk

This Affects:

PHPmagento/extension-b2b
0.0.1 - 1.3.3-p17
Fixed in 1.3.3-2026-aug
1.3.4 - 1.3.4-p16
Fixed in 1.3.4-2026-aug
1.4.0 - 1.4.2-p8
Fixed in 1.4.2-2026-aug
1.5.0 - 1.5.2-p5
Fixed in 1.5.2-2026-aug
1.5.3 - 1.5.3
Fixed in 1.5.3-2026-aug
Are you affected? Scan for Free

TL;DR

magento/extension-b2b fails to enforce authorization on a network-reachable request path. An unauthenticated attacker can escalate privileges and gain elevated access to sensitive resources. The fix corrects the authorization checks so unprivileged callers can no longer obtain that access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

magento/extension-b2b is vulnerable to Incorrect Authorization in versions 1.5.3 - 1.5.3, 1.5.0 - 1.5.2-p5, 1.4.0 - 1.4.2-p8, 1.3.4 - 1.3.4-p16 and 0.0.1 - 1.3.3-p17.

How to fix this

Apply the August 2026 Isolated security patch for your B2B release line (for example 1.5.3-2026-aug). Adobe ships APSB26-92 as Isolated patch files rather than a Composer version bump, so the detected version of the magento/extension-b2b and/or the magento/magento2-b2b-base library does not change after the hotfix — ignore this finding manually in Aikido once the Isolated patch is applied.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform