Adobe Commerce | Incorrect Authorization (CWE-863)
68Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.1epss 25%
from disclosure to weapon4 days
Published on NVDAug 11
1st PoC+4d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
public PoCs found — 1
githubgithub.com/dinosn/cve-2026-71362-magento-lab★ 3⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.