Intel

AIKIDO-2026-458627

magento/product-enterprise-edition is vulnerable to Incorrect Authorization

Incorrect AuthorizationCVE-2026-71362 Published 4 days ago

91

Critical Risk

This Affects:

PHPmagento/product-enterprise-edition
0.0.1 - 2.4.4-p18
Fixed in 2.4.4-2026-aug
2.4.5 - 2.4.5-p17
Fixed in 2.4.5-2026-aug
2.4.6 - 2.4.6-p15
Fixed in 2.4.6-2026-aug
2.4.7 - 2.4.7-p10
Fixed in 2.4.7-2026-aug
2.4.8 - 2.4.8-p5
Fixed in 2.4.8-2026-aug
2.4.9 - 2.4.9
Fixed in 2.4.9-2026-aug
Are you affected? Scan for Free

TL;DR

magento/product-enterprise-edition fails to enforce authorization on a network-reachable request path. An unauthenticated attacker can escalate privileges and gain elevated access to sensitive resources. The fix corrects the authorization checks so unprivileged callers can no longer obtain that access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

magento/product-enterprise-edition is vulnerable to Incorrect Authorization in versions 2.4.9 - 2.4.9, 2.4.8 - 2.4.8-p5, 2.4.7 - 2.4.7-p10, 2.4.6 - 2.4.6-p15, 2.4.5 - 2.4.5-p17 and 0.0.1 - 2.4.4-p18.

How to fix this

Apply the August 2026 Isolated security patch for your release line (for example 2.4.9-2026-aug). Adobe ships APSB26-92 as Isolated patch files rather than a Composer version bump, so the detected version of the magento/product-enterprise-edition and/or the magento/magento2-ee-base library does not change after the hotfix — ignore this finding manually in Aikido once the Isolated patch is applied.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform