CVE-2025-24407: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted leading to both a High impact to confidentiality and Low impact to integrity. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24407?
CVE-2025-24407 has a medium severity rating due to its potential for security feature bypass.
How do I fix CVE-2025-24407?
To fix CVE-2025-24407, upgrade to Adobe Commerce versions later than 2.4.7-beta1.
What versions of Adobe Commerce are affected by CVE-2025-24407?
CVE-2025-24407 affects Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier.
What type of vulnerability is CVE-2025-24407?
CVE-2025-24407 is classified as an Incorrect Authorization vulnerability.
What could an attacker achieve by exploiting CVE-2025-24407?
An attacker exploiting CVE-2025-24407 could bypass security features and perform unauthorized actions.