ZeroHour

CVE-2026-71362

mass

Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)

CVSS 3.1
9.1 critical
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.

What to do: Apply the fix released under Adobe advisory APSB26-92 immediately, prioritizing internet-facing Commerce/Magento instances, and check the bulletin for the exact patched version ranges for your deployment. Because exploitation requires no credentials or user interaction, review admin accounts, API integrations, and user/role assignments for unauthorized privilege changes, and restrict admin-panel and storefront API access where feasible. Monitor Adobe's advisory for indicators of compromise given confirmed in-the-wild exploitation.

Affected
Adobe Commerce (Magento)
Estimated exposure
mass≈200,000+ Magento/Adobe Commerce storefronts worldwide — Public web-technology market-share surveys consistently count Magento/Adobe Commerce deployments in the low hundreds of thousands, and the flaw is exploitable remotely without credentials on standard internet-facing storefronts.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs

Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure

Attackers began exploiting critical Adobe Commerce flaw CVE-2026-71362 (CVSS 9.1) for unauthenticated customer account takeover shortly after patch release.

Sansec blocked the first exploitation attempts of CVE-2026-71362 immediately after Adobe published its advisory. The flaw lets unauthenticated attackers switch a customer session to another customer account, hijacking accounts and accessing private data without credentials, admin privileges or user interaction. It affects Adobe Commerce, Commerce B2B and Magento Open Source versions through the July 2026 patches, and Adobe issued isolated patch files APSB26-92 fixing seven vulnerabilities, including stored cross-site scripting and authorization issues.

Security Affairs · Aug 13, 2026Exploit / PoC in the wildCVE-2026-71362

Adobe security advisory (AV26-808) – Update 1

Canada's Cyber Centre updated Adobe advisory AV26-808 to flag that CVE-2026-71362 in Adobe Commerce is being exploited in the wild.

The Canadian Centre for Cyber Security advisory AV26-808 (Update 1) lists vulnerabilities affecting Adobe products including Campaign Classic, Adobe Commerce, Magento Open Source, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs. Update 1 notes that open-source reporting indicates CVE-2026-71362 is being exploited in the wild. Users and administrators are urged to review the referenced links and apply updates, including those in Adobe bulletin APSB26-92 for Adobe Commerce.

Canadian Centre for Cyber Security · 5d agoAdvisory in the wildCVE-2026-71362

Adobe patches critical Magento account takeover (APSB26-92)

Adobe ships isolated patches (APSB26-92) for Adobe Commerce and Magento Open Source fixing seven flaws, five Critical including account takeover CVE-2026-71362.

Adobe released isolated security patches under APSB26-92 for Adobe Commerce and Magento Open Source addressing seven vulnerabilities, five of them rated Critical. The critical set includes CVE-2026-71362, which Sansec characterizes as enabling account takeover. Merchots running Magento-based stores are urged to apply the patches.