CVE-2026-71362 -- CVSS 9.1 Vulnerability Briefing
CVE-2026-71362 | CVSS 9.1 (Critical) | Exploit: PoC available
What Is It
CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce that could allow an attacker to obtain elevated access to sensitive resources.
Technical Detail
The vulnerability involves insufficient authorization enforcement in Adobe Commerce, creating a path for privilege escalation. An attacker may be able to access resources or functions beyond their intended permission level. Exploitation does not require user interaction and could result in elevated access to sensitive Commerce data or administrative functionality.
Exploitation Status
A proof of concept is available. CISA has not added this vulnerability to the Known Exploited Vulnerabilities catalog, and active exploitation in the wild has not been confirmed by the provided data.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Treat this issue as a critical patching priority and apply Adobe-provided security updates for affected Adobe Commerce deployments as soon as they are available. Review Adobe Commerce administrative accounts, API integrations, role assignments, and access-control configurations for unexpected elevated permissions. Monitor authentication, authorization, administrative-action, and API access logs for access to sensitive resources by accounts that would not normally have the required privileges. No workaround or product-version scope is confirmed in the provided data.