Critical Authorization Bypass in Adobe Commerce & Magento (CVE‑2026‑71362) Enables Account Hijacking
What It Is — Adobe Commerce and Magento contain an incorrect‑authorization flaw that lets an unauthenticated attacker switch a victim’s session to another customer account, exposing private data.
Exploitability — Publicly disclosed; active exploitation attempts observed in the wild; no user interaction required. CVSS not published, but vendor labels it critical.
Affected Products — Adobe Commerce (including Commerce B2B) and Magento release lines prior to the August 2026 security update.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control (CC6.1) requires evidence that privileged‑access mechanisms cannot be bypassed; this flaw directly violates that control.
- Continuous monitoring of patch deployment and session‑management logs provides audit‑ready proof that you remediate critical vulnerabilities promptly.
- Enterprise buyers increasingly demand documented SOC 2 readiness; unpatched session‑hijack bugs are a red flag in security questionnaires.
Recommended Actions
- Deploy Adobe’s August 2026 security update for all supported Commerce, Commerce B2B, and Magento instances immediately.
- Verify that session‑handling logic now enforces proper authorization; run targeted penetration tests to confirm the fix.
- Capture patch‑installation logs and updated WAF rules as evidence for SOC 2 audit trails.
- Review and tighten access‑control policies (e.g., least‑privilege, session timeout) to align with SOC 2 CC6.1 requirements.
Source: BleepingComputer – Hackers exploit critical Adobe Commerce flaw to hijack customer accounts