CVE-2025-24422: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24422?
CVE-2025-24422 is categorized as a low severity vulnerability.
How do I fix CVE-2025-24422?
To remediate CVE-2025-24422, update your Adobe Commerce installation to a version later than 2.4.7-beta1.
Who is affected by CVE-2025-24422?
CVE-2025-24422 affects Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier.
What type of vulnerability is CVE-2025-24422?
CVE-2025-24422 is an Improper Access Control vulnerability that allows for security feature bypass.
Can low-privileged attackers exploit CVE-2025-24422?
Yes, low-privileged attackers can exploit CVE-2025-24422 to bypass certain security measures.