CVE-2025-24409: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both confidentiality and integrity impact. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both a High impact to confidentiality and Low impact to integrity. Exploitation of this issue does not require user interaction.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24409?
CVE-2025-24409 is classified as a high severity vulnerability due to its potential to allow security feature bypass.
How do I fix CVE-2025-24409?
To fix CVE-2025-24409, you should upgrade to Adobe Commerce version 2.4.7 or later.
Who is affected by CVE-2025-24409?
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by CVE-2025-24409.
What could an attacker do with CVE-2025-24409?
An attacker could leverage CVE-2025-24409 to bypass security measures and gain unauthorized access to sensitive information.
When was CVE-2025-24409 announced?
CVE-2025-24409 was announced in 2025 as part of Adobe's regular security updates.