Adobe Commerce/Magento - Customer Session Identity Switch
CVE-2026-71362
Verified
Description
Adobe Commerce contains an incorrect authorization vulnerability caused by improper access control, letting attackers escalate privileges to access sensitive resources, exploit requires no user interaction.
Severity
Critical
CVSS Score
9.1
Exploit Probability
90%
Affected Product
magento
Published Date
August 18, 2026
Template Author
0x_akoko, dinosn
CVE-2026-71362.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-71362
CWE ID:
cwe-863
Remediation Steps
Update to the latest version of Adobe Commerce.