Published on August 13, 2026

[CVE-2026-71362] Critical Adobe Commerce Flaw Allows Unauthenticated Privilege Escalation


Severity
Critical

Detail

Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical, important, and moderate vulnerabilities. Successful exploitation of the vulnerabilities could result in security feature bypass, arbitrary code execution, and privilege escalation. Adobe stated that it is not aware of any exploits in the wild for the issues addressed in the update.

The most severe vulnerability is tracked as CVE-2026-71362, an incorrect authorization vulnerability with a CVSS base score of 9.1 (Critical). The vulnerability can be exploited without authentication or attacker privileges and does not require user interaction.

Successful exploitation could allow attackers to bypass security measures, execute arbitrary code, or elevate privileges within vulnerable e-commerce environments. An attacker with elevated permissions could access sensitive store data, modify application settings, or establish a foothold for further compromise.

CVE IDSummaryCVSS Score
CVE-2026-71362An incorrect authorization vulnerability in Adobe Commerce that can result in privilege escalation. The vulnerability does not require authentication, attacker privileges, or user interaction.9.1 (Critical)

Affected Products

The most severe flaw, CVE-2026-71362 affects Adobe Commerce installations running the July 2026 security-update builds and earlier, specifically versions 2.4.4 through 2.4.9.

The Adobe security bulletin identifies the following affected versions:

• Adobe Commerce: 2.4.4-2026-jul and earlier through 2.4.9-2026-jul and earlier
• Adobe Commerce B2B: 1.3.3-2026-jul and earlier through 1.5.3-2026-jul and earlier
• Magento Open Source: 2.4.6-2026-jul and earlier through 2.4.9-2026-jul and earlier

Recommendation

Adobe recommends that users update their installations to the newest available versions. The security update carries an Adobe Priority 2 rating.

Organizations should upgrade to the August 2026 builds:

• Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, or 2.4.4-2026-aug, depending on the supported release branch.
• Adobe Commerce B2B: corresponding August 2026 packages from 1.3.3 through 1.5.3.
• Magento Open Source: supported August 2026 releases from 2.4.6 through 2.4.9.

GBHackers also recommends reviewing privileged account activity, investigating unexpected configuration changes, validating extension integrity and ensuring appropriate web application firewalls and access-control policies protect exposed Commerce instances.

Source

https://helpx.adobe.com/security/products/magento/apsb26-92.html
https://gbhackers.com/critical-adobe-commerce-flaw/