CVE-2026-71362 – Adobe Commerce

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“A critical authorization flaw can elevate attacker access, while stored scripts put customer and administrator sessions at risk.”

Adobe Commerce is affected by three vulnerabilities involving authorization and stored cross-site scripting. CVE-2026-71362 has a CVSS score of 9.1, Critical severity, and can allow privilege escalation to sensitive resources without user interaction. CVE-2026-48414 has a CVSS score of 7.7, High severity. CVE-2026-48413 has a CVSS score of 8.7, High severity. Both High-severity flaws allow malicious JavaScript to be stored in vulnerable fields and executed in a victim's browser.

The Adobe Commerce security update addresses these weaknesses, reducing the risk of unauthorized privilege gains and compromise of user accounts or sessions.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-863
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.