Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Hackers exploit a critical vulnerability in Adobe's Commerce and Magento e-commerce platforms, potentially allowing them to hijack customer accounts. The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive r…
Intelligence analysis by Llama

A critical vulnerability in Adobe's Commerce and Magento e-commerce platforms has been detected, potentially allowing hackers to hijack customer accounts. The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive resources without authentication.
Imagine you have an online store where people can buy things from you. Hackers found a way to break into the system and take control of people's accounts, so they can buy things without paying for them. This is a big problem because it could let hackers steal people's money or personal information.
Analysis
Critical Vulnerability in Adobe Commerce and Magento E-commerce Platforms Detected
A critical vulnerability in Adobe's Commerce and Magento e-commerce platforms has been detected, potentially allowing hackers to hijack customer accounts. The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive resources without authentication.
According to Sansec, a security company that has been analyzing Adobe's patch, the vulnerability lets attackers switch a customer session to another customer account, giving them access to the victim's account and private customer data. This is a significant concern for e-commerce businesses that rely on Adobe's Commerce and Magento platforms.
The vulnerability, identified as CVE-2026-71362, is one of the seven issues that Adobe addressed in a security update yesterday. Although Adobe states that it is not aware of exploits in the wild for any of the fixed flaws, Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026-71362 exploitation attempts.
Sansec's analysis of Adobe's patch reveals that the vulnerability is caused by Magento improperly handling customer identity in an account session. This allows attackers to exploit the vulnerability without requiring any existing account, administrator privileges, or user interaction.
The implications of this vulnerability are significant, and e-commerce businesses that rely on Adobe's Commerce and Magento platforms should take immediate action to address the issue. This includes applying the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.
Four Other Flaws Fixed in Adobe's Security Update
In addition to the critical vulnerability in Adobe's Commerce and Magento e-commerce platforms, Adobe's security update also addressed four other flaws. These flaws, identified as CVE-2026-48414, CVE-2026-48413, CVE-2026-48415, and CVE-2026-48416, received a high-severity score and could potentially be exploited by attackers.
CVE-2026-48414 is a stored cross-site scripting vulnerability that could result in arbitrary code execution. Exploitation requires authentication and administrator privileges.
CVE-2026-48413 is also a stored cross-site scripting vulnerability that could result in arbitrary code execution. It requires authentication but not administrator privileges.
CVE-2026-48415 is an incorrect-authorization vulnerability affecting Adobe Commerce B2B that could enable a security-feature bypass. It requires authentication but not administrator privileges.
CVE-2026-48416 is an incorrect-authorization vulnerability that could enable a security-feature bypass. It requires neither authentication nor administrator privileges.
Website Administrators Should Take Immediate Action
Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible. This includes ensuring that they are running the latest -p release available for their supported release branch before applying the corresponding isolated patch.
Once attackers have valid credentials, only 37% of their actions are blocked. Overall prevention scores can hide what happens after initial access. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Key points
- A critical vulnerability in Adobe's Commerce and Magento e-commerce platforms has been detected, potentially allowing hackers to hijack customer accounts.
- The flaw, described as an incorrect authorization vulnerability, could be leveraged to gain elevated access to sensitive resources without authentication.
- Website administrators are advised to apply the August 2026 security update for currently supported Commerce, Commerce B2B, and Magento release lines as soon as possible.
- The vulnerability, identified as CVE-2026-71362, is one of the seven issues that Adobe addressed in a security update yesterday.
- Sansec's analysis of Adobe's patch reveals that the vulnerability is caused by Magento improperly handling customer identity in an account session.
If the vulnerability is patched quickly, e-commerce businesses can prevent hackers from exploiting it. This could help to prevent financial losses and protect customer data.
If the vulnerability is not patched quickly, hackers could continue to exploit it, leading to financial losses and data breaches for e-commerce businesses.


