Adobe Commerce and Magento Open Source Incorrect Authorization Account Takeover Vulnerability

Release Date: 24th September 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s), particularly businesses and government bodies operating online stores or customer portals on Adobe Commerce or Magento. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-71362 is a critical incorrect authorization vulnerability (CWE-863) affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The flaw lies in how the platform handles customer identity within account sessions, allowing an unauthenticated remote attacker to switch a customer session to another customer's account. CVSS v3.1 score: 9.1 (Critical) - AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.

Reference

  1. https://helpx.adobe.com/security/products/magento/apsb26-92.html
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-71362