PT-2026-70824 · Adobe · Commerce+1
CVE-2026-71362
·
Published
2026-08-11
·
Updated
2026-09-08
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Commerce (affected versions not specified)
Magento Open Source (affected versions not specified)
Description
An incorrect authorization issue allows unauthenticated remote attackers to bypass authentication controls and hijack customer accounts via crafted HTTP requests. This can lead to privilege escalation, granting elevated access to sensitive resources, and may result in data theft, credential stuffing, and financial fraud. Real-world incidents of active exploitation have been reported.
Recommendations
Apply the security patch immediately.
Implement WAF rules to block suspicious request patterns targeting authentication endpoints.
Enable MFA on all customer accounts as a compensating control.
Monitor for spikes in account recovery or password reset requests.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commerce
Magento Open Source