CVE-2026-71362 is a CVSS 3.1 9.1 incorrect-authorization vulnerability in Adobe Commerce and Magento Open Source that results in privilege escalation, allowing an attacker to gain elevated access to sensitive resources. Exploitation does not require user interaction.
CISA added it to the Known Exploited Vulnerabilities catalog on 24 September 2026. The flaw is the same one ASD's Australian Cyber Security Centre rated critical on 9 September 2026, when it warned of active exploitation in Adobe Commerce and Magento Open Source — so the KEV addition converts a national alert into a US federal remediation obligation rather than disclosing a new defect.
Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-71362 |
| CVSS | 9.1 (NVD, CVSS 3.1) — Critical |
| Vendor / product | Adobe Commerce and Magento Open Source |
| Type | Incorrect authorization → privilege escalation |
| User interaction | None required |
| Status | In CISA KEV as of 24 September 2026; ACSC critical alert, 9 September 2026 |
| Reported | 24 September 2026 (KEV addition) |
Mitigation
Patch to the vendor's fixed release. Because the mechanism is an authorization failure rather than a memory-safety bug, there is no configuration workaround that reliably closes it, and the absence of a user-interaction requirement means the attack surface is the storefront or admin endpoint itself. Merchants should also treat prior exposure as a possibility: the ACSC's 9 September alert and the subsequent KEV listing together indicate exploitation predates the US catalogue entry, so a post-patch review of administrative account creation and privilege changes is warranted.