CVE-2025-24418: Adobe Commerce | Improper Authorization (CWE-285)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24418?
CVE-2025-24418 has a low severity rating, indicating a potential risk for privilege escalation.
How do I fix CVE-2025-24418?
To fix CVE-2025-24418, you should upgrade Adobe Commerce to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-24418?
CVE-2025-24418 affects Adobe Commerce versions up to and including 2.4.7-beta1.
What type of vulnerability is CVE-2025-24418?
CVE-2025-24418 is classified as an Improper Authorization vulnerability.
Can a low-privileged attacker exploit CVE-2025-24418?
Yes, a low-privileged attacker could exploit CVE-2025-24418 to bypass security measures and gain elevated privileges.