→ Back to Home
Application Security

Critical Adobe Commerce Flaw Actively Exploited for Customer Account Hijacking

A critical incorrect-authorization vulnerability, identified as CVE-2026-71362, has been discovered and is actively being exploited in Adobe Commerce and Magento platforms. This flaw allows attackers to gain elevated access to sensitive resources without requiring any prior authentication. Security researchers have observed live exploitation attempts where the vulnerability enables attackers to switch a live customer session into another customer's account, effectively hijacking their session. This vulnerability carries profound implications for any business operating on Adobe Commerce or Magento. Unlike generic application bugs, a session hijacking flaw directly compromises customer identity, stored personal and payment data, order history, and, most importantly, customer trust. The blast radius extends far beyond mere application availability, touching upon brand reputation and potential financial liabilities. The fact that exploitation requires no existing account, no admin privileges, and no user interaction makes it an extremely potent threat that can be leveraged broadly by attackers. This incident fits into a broader, well-established trend in application security where authorization flaws consistently rank among the most critical risks, as highlighted by frameworks like the OWASP Top 10. As e-commerce platforms become central to business operations, they increasingly become high-value targets. Attackers are constantly seeking vulnerabilities in business logic, authentication, and authorization mechanisms to directly impact revenue streams and customer data. The rapid exploitation of this flaw underscores the need for continuous security vigilance and a secure-by-design approach, especially for platforms handling sensitive customer interactions and financial transactions. The increasing use of generative AI by threat actors to accelerate attack stages, as noted in Verizon's 2026 DBIR, further intensifies the pressure on application security teams to respond quickly and effectively. In practice, organizations utilizing Adobe Commerce, Commerce B2B, or Magento instances must act immediately. The primary recommendation is to identify all deployed instances, including less visible regional or brand storefronts, and apply the August 2026 isolated patch containing the fix for CVE-2026-71362. Beyond patching, security teams should review logs and telemetry for any suspicious customer-session changes, anomalous login-to-account transitions, or customer support complaints that might indicate session hijacking. If immediate patching is not feasible, tightening monitoring around customer account access, session handling, and Web Application Firewall (WAF) detections related to this flaw is crucial. Given the potential impact on customer trust, legal, support, and e-commerce stakeholders should be made aware of the situation and involved in the response strategy.
#adobe commerce#magento#cve#session hijacking#e-commerce security#critical vulnerability
Read original source