CVE-2025-24426: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24426?
CVE-2025-24426 is classified as a low-severity vulnerability that allows for a security feature bypass.
How do I fix CVE-2025-24426?
To remediate CVE-2025-24426, ensure that you upgrade to Adobe Commerce version 2.4.7 or later.
Who is affected by CVE-2025-24426?
CVE-2025-24426 affects Adobe Commerce versions up to and including 2.4.7-beta1.
What type of vulnerability is CVE-2025-24426?
CVE-2025-24426 is an Improper Access Control vulnerability.
Can a low-privileged attacker exploit CVE-2025-24426?
Yes, a low-privileged attacker can exploit CVE-2025-24426 to bypass security measures.