SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-71362 2026-08-11

Adobe Commerce Privilege Escalation: CVE-2026-71362 Rates CVSS 9.1

"Adobe disclosed a critical Incorrect Authorization flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that, per Adobe's advisory, could result in privilege escalation, potentially allowing an…"

Adobe disclosed a critical Incorrect Authorization flaw in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that, per Adobe's advisory, could result in privilege escalation, potentially allowing an unauthenticated, remote attacker to gain elevated access to sensitive resources without any user interaction.

What Is It

CVE-2026-71362 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Commerce. Per Adobe's advisory, the flaw "could result in privilege escalation," and "an attacker could leverage this vulnerability to gain elevated access to sensitive resources." Exploitation does not require user interaction.

Adobe's PSIRT scored it CVSS 3.1 base 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, network attack vector, low attack complexity, no privileges required, no user interaction, with high confidentiality and integrity impact and no availability impact. The exploitability subscore is a maximum 3.9.

Why It Matters

Every barrier to exploitation is absent: no credentials, no victim interaction, remotely reachable, and low complexity. That combination on a storefront platform means an attacker who can reach the application can attempt escalation directly. The high confidentiality and integrity impact ratings mean both data disclosure and data modification are in scope.

Note: this CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. There is no confirmation of active exploitation in the supplied source material. NVD status is "Received," meaning the record is still awaiting full analysis.

What's Vulnerable

Per Adobe's affected-product data:

One caveat on the Adobe Commerce row: Adobe's affected-product data also names 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, and 2.4.4-2026-aug, the same builds the bulletin lists as unaffected. Those five entries appear on both sides of the advisory, so treat them as unresolved and confirm your specific branch against APSB26-92 before concluding you are patched or exposed.

Patch Status

Patched builds are available. Adobe lists these releases as unaffected:

The upgrade path is the August 2026 release train for whichever branch you run. No KEV-mandated remediation deadline applies, as the CVE is not in the catalog.

Sources