Adobe Commerce and Magento Open Source Incorrect Authorization Account Takeover Vulnerability
Release Date: 24th September 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s), particularly businesses and government bodies operating online stores or customer portals on Adobe Commerce or Magento. This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-71362 is a critical incorrect authorization vulnerability (CWE-863) affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The flaw lies in how the platform handles customer identity within account sessions, allowing an unauthenticated remote attacker to switch a customer session to another customer's account. CVSS v3.1 score: 9.1 (Critical) - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.
What are the systems affected?
The following versions are affected, up to and including the July 2026 patch releases:
Adobe Commerce 2.4.4 through 2.4.9 (2026-jul and earlier) – (Affected)
Adobe Commerce B2B 1.3.3 through 1.5.3 (2026-jul and earlier) – (Affected)
Magento Open Source 2.4.6 through 2.4.9 (2026-jul and earlier) – (Affected)
Not affected / patched version:
Adobe Commerce 2.4.4-2026-aug through 2.4.9-2026-aug, Adobe Commerce B2B 1.3.3-2026-aug through 1.5.3-2026-aug, and Magento Open Source 2.4.6-2026-aug through 2.4.9-2026-aug (APSB26-92) – (Not affected)
What does this mean?
Successful exploitation may allow attackers to:
- Take over customer accounts on an affected store without knowing any credentials
- Access private customer data, including personal details, addresses, and order history
- Perform actions as the victim customer, such as viewing or changing account information and placing orders
Mitigation process?
CERTVU recommends the following:
-
Apply the Vendor Patch Immediately
Install the August 2026 patch release from Adobe security bulletin APSB26-92 for your Adobe Commerce, Commerce B2B, or Magento Open Source version. Adobe also provides isolated patch files for stores that cannot upgrade immediately. -
Verify the Patch Is Applied
-
Treat This as Top Priority
-
Monitor for Customer Session Anomalies
-
Review Internet Exposure
Reference
- https://helpx.adobe.com/security/products/magento/apsb26-92.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-71362
- Download advisory (English): Adobe Commerce and Magento Open Source Incorrect Authorization Account Takeover Vulnerability