magento/extension-b2b is vulnerable to Incorrect Authorization
86
High Risk
magento/extension-b2b fails to enforce authorization on a network-reachable request path. An unauthenticated attacker can escalate privileges and gain elevated access to restricted resources across a changed scope. The fix corrects the authorization checks so unprivileged callers can no longer obtain that access.
You are affected if you are using a version that falls within the vulnerable range.
magento/extension-b2b is vulnerable to Incorrect Authorization in versions 1.5.3 - 1.5.3, 1.5.0 - 1.5.2-p5, 1.4.0 - 1.4.2-p8, 1.3.4 - 1.3.4-p16 and 0.0.1 - 1.3.3-p17.
Apply the September 2026 Isolated security patch for your B2B release line (for example 1.5.3-2026-sep; see https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-44020). Adobe ships APSB26-138 as Isolated patch files rather than a Composer version bump, so the detected version of the magento/extension-b2b and/or the magento/magento2-b2b-base library does not change after the hotfix — ignore this finding manually in Aikido once the Isolated patch is applied.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.