PT-2026-70824 · Adobe · Commerce+1

CVE-2026-71362

·

Published

2026-08-11

·

Updated

2026-09-08

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Adobe Commerce (affected versions not specified) Magento Open Source (affected versions not specified)
Description An incorrect authorization issue allows unauthenticated remote attackers to bypass authentication controls and hijack customer accounts via crafted HTTP requests. This can lead to privilege escalation, granting elevated access to sensitive resources, and may result in data theft, credential stuffing, and financial fraud. Real-world incidents of active exploitation have been reported.
Recommendations Apply the security patch immediately. Implement WAF rules to block suspicious request patterns targeting authentication endpoints. Enable MFA on all customer accounts as a compensating control. Monitor for spikes in account recovery or password reset requests.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11928
CVE-2026-71362

Affected Products

Commerce
Magento Open Source