No password. No account. No click. Just someone else's customer session.
CVE-2026-71362 is a CVSS 9.1 incorrect authorization flaw in Adobe Commerce and Magento Open Source. It lets an attacker with no account, no privileges and no help from the victim…
Read the brief