TechNewsReel
Live

Adobe Patches Critical Magento Flaw Allowing Unauthenticated Account Hijacks

A high-severity vulnerability in Adobe Commerce and Magento Open Source lets attackers seize customer accounts without any user interaction.

TechNewsReel Newsroom · August 13, 2026

Adobe has released a critical security update to address a vulnerability in Adobe Commerce and Magento Open Source that allows unauthenticated attackers to hijack customer accounts. The flaw, tracked as CVE-2026-71362, enables remote actors to switch a session to another customer's account, granting immediate access to private data.

The vulnerability carries a CVSS base score of 9.1. According to Adobe and security research firm Sansec, exploitation requires no authentication, no administrator privileges, and zero user interaction. By manipulating the session, an attacker can effectively impersonate any customer on the platform. Adobe distributed the fix on August 11, 2026, as part of security bulletin APSB26-92, which addressed this flaw alongside six other vulnerabilities, including stored XSS and B2B-specific authorization bypasses.

The Mechanics of the Breach

Adobe Commerce and Magento Open Source serve as the backbone for thousands of global e-commerce stores. The vulnerability is categorized as an incorrect authorization flaw. Sansec noted that the vulnerability specifically lets attackers switch a customer session to another account, providing direct access to the victim's account and their private customer data.

This release follows Adobe's current patching strategy, where the company distributes isolated patch files on a monthly basis to provide rapid mitigation before these fixes are integrated into comprehensive full security releases. This approach is designed to reduce the window of exposure for merchants running these widely used platforms.

Industry Implications

Because the exploit is unauthenticated and requires no interaction from the victim, any store running a vulnerable version of the software is at high risk of mass account takeovers. The potential for automated exploitation means that thousands of accounts could be compromised in a short window. Such breaches typically lead to the theft of sensitive personally identifiable information (PII) and financial data, which can result in severe regulatory penalties and a total collapse of merchant trust.

Current Status and Outlook

While Adobe has provided the necessary patches, the threat remains active. Reports from BleepingComputer indicate that attempts to exploit CVE-2026-71362 have already been detected in the wild, suggesting that threat actors were aware of the flaw and began targeting stores before or immediately after the patch release.

Merchants are urged to apply the APSB26-92 updates immediately. Security teams should monitor session logs for unusual activity and verify that all isolated patches from the August update have been correctly deployed to prevent unauthorized account access.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.