helpx.adobe.comVendor advisory
https://helpx.adobe.com/security/products/magento/apsb26-92.html CVE-2026-71362
CRITICAL
Adobe Commerce | Incorrect Authorization (CWE-863)
Record summary
CVE-2026-71362 has a selected CVSS score of 9.1 (critical).
Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 12, 2026 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Adobe CommerceBrowse Adobe / Adobe CommerceDefault status: affected | CVE List | Through 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | affected |
| 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug | unaffected | ||
Adobe Commerce B2BBrowse Adobe / Adobe Commerce B2BDefault status: affected | CVE List | Through 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul | affected |
| 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug | unaffected | ||
Magento Open SourceBrowse Adobe / Magento Open SourceDefault status: affected | CVE List | Through 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul | affected |
| 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug | unaffected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-71362