Intel

AIKIDO-2026-269443

magento/extension-b2b is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-77109 Published 4 days ago

86

High Risk

This Affects:

PHPmagento/extension-b2b
0.0.1 - 1.3.3-p17
Fixed in 1.3.3-2026-sep
1.3.4 - 1.3.4-p16
Fixed in 1.3.4-2026-sep
1.4.0 - 1.4.2-p8
Fixed in 1.4.2-2026-sep
1.5.0 - 1.5.2-p5
Fixed in 1.5.2-2026-sep
1.5.3 - 1.5.3
Fixed in 1.5.3-2026-sep
Are you affected? Scan for Free

TL;DR

magento/extension-b2b fails to enforce authorization on a network-reachable request path. An unauthenticated attacker can escalate privileges and gain elevated access to restricted resources across a changed scope. The fix corrects the authorization checks so unprivileged callers can no longer obtain that access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

magento/extension-b2b is vulnerable to Incorrect Authorization in versions 1.5.3 - 1.5.3, 1.5.0 - 1.5.2-p5, 1.4.0 - 1.4.2-p8, 1.3.4 - 1.3.4-p16 and 0.0.1 - 1.3.3-p17.

How to fix this

Apply the September 2026 Isolated security patch for your B2B release line (for example 1.5.3-2026-sep; see https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-44020). Adobe ships APSB26-138 as Isolated patch files rather than a Composer version bump, so the detected version of the magento/extension-b2b and/or the magento/magento2-b2b-base library does not change after the hotfix — ignore this finding manually in Aikido once the Isolated patch is applied.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform