CVE-2025-24420: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24420?
CVE-2025-24420 is classified as a low severity vulnerability in Adobe Commerce.
How do I fix CVE-2025-24420?
To fix CVE-2025-24420, upgrade your Adobe Commerce to version 2.4.7-beta2 or later.
Who is affected by CVE-2025-24420?
CVE-2025-24420 affects Adobe Commerce versions 2.4.7-beta1 and earlier.
What type of vulnerability is CVE-2025-24420?
CVE-2025-24420 is an Incorrect Authorization vulnerability that may lead to security feature bypass.
Can a low-privileged attacker exploit CVE-2025-24420?
Yes, a low-privileged attacker can exploit CVE-2025-24420 to perform unauthorized actions.