Incorrect Authorization Vulnerability in Adobe Commerce
CVE-2026-71362

9.1CRITICAL

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 August 2026

Badges

πŸ“ˆ Score: 396πŸ‘Ύ Exploit Exists🟑 Public PoC🟣 EPSS 25%πŸ“° News Worthy

What is CVE-2026-71362?

CVE-2026-71362 is an identified vulnerability in Adobe Commerce, a versatile e-commerce platform utilized by businesses to create and manage online stores. This specific vulnerability is classified as an Incorrect Authorization flaw, which opens the door for potential privilege escalation. By exploiting this weakness, an attacker can elevate their access privileges without the need for user interaction, thereby possibly gaining access to sensitive data and functionalities contained within the platform. Given Adobe Commerce's integration into various business operations, the consequences of such an exploitation could severely disrupt organizational integrity and customer trust.

Potential impact of CVE-2026-71362

  1. Unauthorized Access to Sensitive Information: Attackers leveraging this vulnerability can infiltrate protected areas of the Adobe Commerce platform, accessing confidential customer data, financial transactions, or proprietary business information, which can lead to data breaches and regulatory ramifications.

  2. Escalation of Privileges: This vulnerability enables unauthorized users to gain higher-level permissions, allowing them to perform administrative actions, modify configurations, or manipulate site content without legitimate oversight. Such actions can undermine the integrity of the e-commerce operations and could lead to data manipulation or fraudulent transactions.

  3. Increased Risk of System Compromise: The ability of an attacker to escalate privileges means they can potentially install malware, create backdoors, or engage in further exploitations, thus compromising the entire e-commerce environment and leading to prolonged downtime or loss of revenue due to system unavailability.

Affected Version(s)

Adobe Commerce 0 <= 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug

Adobe Commerce B2B 0 <= 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul

Magento Open Source 0 <= 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.

3 weeks ago

References

EPSS Score

25% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.