CVE-2025-24427: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
— NVD
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24427?
CVE-2025-24427 is considered a low-severity vulnerability affecting Adobe Commerce.
What are the affected versions for CVE-2025-24427?
CVE-2025-24427 affects Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and 2.4.4-p11 and earlier.
How do I fix CVE-2025-24427?
To remediate CVE-2025-24427, upgrade to the latest version of Adobe Commerce that addresses the vulnerability.
What type of vulnerability is CVE-2025-24427?
CVE-2025-24427 is classified as an Improper Access Control vulnerability.
Who can exploit CVE-2025-24427?
A low-privileged attacker can potentially exploit CVE-2025-24427 to bypass security measures.