CVE-2025-24421: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted. Exploitation of this issue does not require user interaction.
— NVD
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to read select data. Exploitation of this issue does not require user interaction
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24421?
CVE-2025-24421 is classified as a low severity vulnerability.
How do I fix CVE-2025-24421?
To fix CVE-2025-24421, update Adobe Commerce to the latest patched version.
Who is affected by CVE-2025-24421?
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and 2.4.4-p11 and earlier are affected by CVE-2025-24421.
What could an attacker do by exploiting CVE-2025-24421?
An attacker could exploit CVE-2025-24421 to perform unauthorized actions due to a security feature bypass.
What types of systems are impacted by CVE-2025-24421?
CVE-2025-24421 impacts systems running Adobe Commerce and various versions of Magento Commerce.