Knox CVE Database
/
CVE-2026-71362
Critical
9.1

CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Added to the CISA KEV catalog:
September 24, 2026

Overview

Adobe Commerce and Magento contain an incorrect authorization flaw that allows an unauthenticated remote attacker to bypass access controls and gain elevated privileges over sensitive store data and configuration. No user interaction is required. Affected versions span the 2.4.x release lines of both Commerce and Magento Open Source, as well as the Commerce B2B extension across its supported branches. Fixed builds were released in the August 2026 security update cycle.

Vulnerability details

Affected vendor
Adobe
Affected product
Commerce and Magento
Weakness type (CWE)
CWE-863

CWE-863 (Incorrect Authorization) describes a condition where an application performs an authorization check but applies the wrong policy, checks the wrong resource, or evaluates the wrong principal, causing a request that should be denied to succeed. In Adobe Commerce and Magento, the authorization logic governing access to sensitive resources contains such a flaw. The check runs but produces an incorrect result for crafted requests, allowing the application to grant access it should refuse. Because the flaw sits in the authorization layer rather than the authentication layer, no credentials are needed to reach it.


An unauthenticated attacker sends a crafted network request targeting the vulnerable authorization path. The application incorrectly evaluates the request as authorized and grants elevated access. The attacker gains both read and write access to sensitive resources, consistent with high confidentiality and high integrity impact. No preconditions beyond network reachability are stated. The specific endpoint or parameter structure involved is not disclosed in available sources, but the attack requires no prior foothold and no victim interaction, making internet-exposed storefronts the primary risk surface.

Severity and impact

9.1
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review web server and application access logs for requests that result in HTTP 200 responses to administrative or privileged API endpoints from sessions with no corresponding authentication event, particularly from sources with no prior login history.
  • Monitor for unexpected changes to store configuration, admin user accounts, or order and customer data that cannot be attributed to a logged-in administrator session, which may indicate post-exploitation write activity.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 27, 2026

Additional hardening

  • Upgrade Adobe Commerce to the August 2026 security release for your branch (2.4.4 through 2.4.9) and Magento Open Source to the corresponding August 2026 builds. Commerce B2B users should apply the matching August 2026 B2B release. See References for the vendor advisory.
  • Restrict access to Commerce and Magento admin paths and API endpoints at the network perimeter or WAF layer, limiting exposure to known IP ranges rather than the open internet.
  • Audit admin user accounts and privileged API credentials for unexpected additions or modifications, and review recent order, customer, and configuration changes for signs of unauthorized access.
  • Apply principle of least privilege to service accounts and integrations connected to the Commerce instance, reducing the blast radius if an attacker gains elevated access through this or a related flaw.

Key dates

Published (NVD)
August 11, 2026
Added to CISA KEV
September 24, 2026
Remediation deadline
September 27, 2026
Last updated
September 25, 2026

References

Frequently asked questions

Does CVE-2026-71362 affect my FedRAMP authorization?

If Adobe Commerce and Magento runs inside your authorization boundary, yes. CVE-2026-71362 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its September 27, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV in the boundary is a finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Your options are to remediate it immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-71362?

Knox does not patch your software. Remediating Adobe Commerce and Magento is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. Applying the patch is yours to own; managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-71362 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at review time. That difference in timing is what gives you room to act before a finding becomes a formal conversation.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-71362's remediation deadline of September 27, 2026 has passed. What happens now?

If CVE-2026-71362 remains unremediated in your boundary, it sits as an open Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Closing the finding and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.