Intel

AIKIDO-2026-513135

magento/product-community-edition is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-76202 Published 4 days ago

82

High Risk

This Affects:

PHPmagento/product-community-edition
0.0.1 - 2.4.6-p15
Fixed in 2.4.6-2026-sep
2.4.7 - 2.4.7-p10
Fixed in 2.4.7-2026-sep
2.4.8 - 2.4.8-p5
Fixed in 2.4.8-2026-sep
2.4.9 - 2.4.9
Fixed in 2.4.9-2026-sep
Are you affected? Scan for Free

TL;DR

magento/product-community-edition fails to enforce authorization on a network-reachable request path. An unauthenticated attacker can escalate privileges and gain elevated access to sensitive information. The fix corrects the authorization checks so unprivileged callers can no longer obtain that access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

magento/product-community-edition is vulnerable to Incorrect Authorization in versions 2.4.9 - 2.4.9, 2.4.8 - 2.4.8-p5, 2.4.7 - 2.4.7-p10 and 0.0.1 - 2.4.6-p15.

How to fix this

Apply the September 2026 Isolated security patch for your release line (for example 2.4.9-2026-sep; see https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-44020). Adobe ships APSB26-138 as Isolated patch files rather than a Composer version bump, so the detected version of the magento/product-community-edition and/or the magento/magento2-base library does not change after the hotfix — ignore this finding manually in Aikido once the Isolated patch is applied.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform