---
id: CVE-2026-71362
title: >-
  Adobe Commerce is affected by an Incorrect Authorization vulnerability that
  could result in privilege escalation
summary: >-
  Adobe Commerce is affected by an Incorrect Authorization vulnerability that
  could result in privilege escalation. An attacker could leverage this
  vulnerability to gain elevated access to sensitive resources. Exploitation of
  this issue do…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
vendor: adobe
product: commerce
affected:
  - commerce < 2.4.4
  - commerce = 2.4.4
  - commerce = 2.4.5
  - commerce = 2.4.6
  - commerce = 2.4.7
  - commerce = 2.4.8
  - commerce = 2.4.9
  - commerce_b2b < 1.3.3
  - commerce_b2b = 1.3.3
  - commerce_b2b = 1.3.4
  - commerce_b2b = 1.4.2
  - commerce_b2b = 1.5.2
  - commerce_b2b = 1.5.3
  - magento <= 2.4.6
  - magento = 2.4.7
  - magento = 2.4.8
  - magento = 2.4.9
patched:
  - commerce 2.4.4
  - commerce_b2b 1.3.3
published: '2026-08-11'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T12:53:15.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71362'
references:
  - url: 'https://helpx.adobe.com/security/products/magento/apsb26-92.html'
    label: psirt@adobe.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-71362
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.89616
epssPercentile: 0.99783
kev: true
kevDateAdded: '2026-09-24'
kevDueDate: '2026-09-27'
kevRansomware: false
exploited: true
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/dinosn/cve-2026-71362-magento-lab'
  nuclei:
    - CVE-2026-71362
  checkedAt: '2026-09-26T09:05:57.818Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-24T19:40:07.950551Z'
ingestedAt: '2026-09-15T14:38:16.180Z'
---

## Overview

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

## Affected

- `commerce < 2.4.4`
- `commerce = 2.4.4`
- `commerce = 2.4.5`
- `commerce = 2.4.6`
- `commerce = 2.4.7`
- `commerce = 2.4.8`
- `commerce = 2.4.9`
- `commerce_b2b < 1.3.3`
- `commerce_b2b = 1.3.3`
- `commerce_b2b = 1.3.4`
- `commerce_b2b = 1.4.2`
- `commerce_b2b = 1.5.2`
- `commerce_b2b = 1.5.3`
- `magento <= 2.4.6`
- `magento = 2.4.7`
- `magento = 2.4.8`
- `magento = 2.4.9`

## Remediation

Upgrade past the affected range:

- `commerce 2.4.4`
- `commerce_b2b 1.3.3`
