Summary
CVE-2026-71362 is an Incorrect Authorization vulnerability (CWE-863) affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The flaw allows an unauthenticated, remote attacker to escalate privileges and obtain elevated access to the application without any user interaction. Adobe rates this issue Critical with a CVSS v3.1 base score of 9.1.
Technical details
- Root cause: The application fails to correctly enforce authorization checks (CWE-863: Incorrect Authorization), allowing access-control decisions to be bypassed.
- Trigger conditions: No authentication or user interaction is required; the flaw can be triggered by a remote, unauthenticated attacker sending requests over the network.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality and integrity impact (privilege escalation and elevated access to protected data/functions); no direct impact on availability per the CVSS vector.
Affected software
- Adobe Commerce: versions 2.4.4 through 2.4.9 (up to and including the July 2026 security releases, e.g. 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug)
- Adobe Commerce B2B: versions 1.3.3 through 1.5.3 (up to and including 2026-jul releases)
- Magento Open Source: versions 2.4.6 through 2.4.9 (up to and including 2026-jul releases)
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to the August 2026 patch releases (e.g., 2.4.9-2026-aug and later, or the corresponding patched version for your branch) as published in Adobe Security Bulletin APSB26-92.
- If no patch can be applied immediately: Restrict administrative and application network exposure where feasible, monitor for anomalous authorization/privilege-related activity, and prioritize patching given the unauthenticated, network-exploitable nature of this issue.

