/Vulnerability Library

Adobe Commerce/Magento - Customer Session Identity Switch

CVE-2026-71362
Verified

Description

Adobe Commerce contains an incorrect authorization vulnerability caused by improper access control, letting attackers escalate privileges to access sensitive resources, exploit requires no user interaction.

Severity

Critical

CVSS Score

9.1

Exploit Probability

90%

Affected Product

magento

Published Date

August 18, 2026

Template Author

0x_akoko, dinosn

CVE-2026-71362.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE ID:
cve-2026-71362
CWE ID:
cwe-863

References

https://helpx.adobe.com/security/products/magento/apsb26-92.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2026-71362https://sansec.io/research/adobe-commerce-account-takeover-apsb26-92https://github.com/dinosn/cve-2026-71362-magento-lab

Remediation Steps

Update to the latest version of Adobe Commerce.