Critical Adobe Commerce and Magento Vulnerability Could Enable Customer Account Takeovers
Security researchers have detected attempts to exploit a critical vulnerability, tracked as CVE-2026-71362, in Adobe Commerce and Magento e-commerce platforms. The flaw could allow unauthenticated attackers to take over customer accounts and access sensitive personal information.
Adobe describes the issue as an authentication vulnerability that could enable attackers to gain elevated access to sensitive resources without logging in. CVE-2026-71362 is one of seven security vulnerabilities addressed in Adobe’s latest security update.
Although Adobe has published a security advisory, e-commerce security firm Sansec said it is not currently aware of active exploits targeting the patched vulnerability. The company also confirmed that its Shield web application firewall (WAF) is blocking attempts to exploit CVE-2026-71362.
Exploitation of CVE-2026-71362 does not require an existing customer account, administrative privileges, or user interaction, according to Sansec.
After analyzing Adobe’s patch, researchers found that Magento improperly handles customer IDs within account sessions. This weakness could allow attackers to manipulate session data and access another customer’s account.
“Sansec has investigated the patch and determined that this vulnerability allows an attacker to switch a customer session to another customer account. This allows the attacker to access the victim’s account and personal customer data,” the security company explained.
Other Adobe Commerce and Magento vulnerabilities fixed
Adobe’s security update also addresses six additional vulnerabilities. Four received high-severity ratings, while the remaining issues were classified as medium and low severity:
- CVE-2026-48414 (CVSS 7.7, High): A stored cross-site scripting vulnerability that could lead to arbitrary code execution. Exploitation requires authentication and administrator privileges.
- CVE-2026-48413 (CVSS 8.7, High): A stored cross-site scripting vulnerability that could lead to arbitrary code execution. Authentication is required, but administrator privileges are not.
- CVE-2026-48415 (CVSS 7.6, High): An authentication vulnerability affecting Adobe Commerce B2B that could allow security feature bypasses. Authentication is required, but administrator privileges are not.
- CVE-2026-48416 (CVSS 7.5, High): An authentication vulnerability that could allow security feature bypasses. Exploitation does not require authentication or administrator privileges.
- CVE-2026-48411 (CVSS 6.5, Medium): An authentication vulnerability that could allow security feature bypasses. Exploitation requires authentication and administrator privileges.
- CVE-2026-48412 (CVSS 2.7, Low): An authentication vulnerability that could lead to privilege escalation. Exploitation requires authentication and administrator privileges.
Adobe Commerce and Magento administrators urged to patch
Website administrators should apply the August 2026 security updates to all supported Adobe Commerce, Adobe Commerce B2B, and Magento release branches as soon as possible. The updates are particularly important for online stores that process customer accounts, payment information, and other sensitive data.
According to Sansec, Adobe distributes these monthly fixes as separate patch files rather than as new security releases or updated Composer packages.
Before applying the corresponding security patch, administrators should confirm that their installation is running the latest patch release available for a supported release branch. Organizations should also review authentication logs, customer sessions, and web application firewall alerts for signs of attempted exploitation.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




