CVE-2025-24434: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
Other sources
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24434?
CVE-2025-24434 is considered a critical vulnerability due to its potential for privilege escalation and unauthorized access.
How do I fix CVE-2025-24434?
To fix CVE-2025-24434, update your Adobe Commerce software to versions 2.4.7-beta2 or later.
Which versions of Adobe Commerce are affected by CVE-2025-24434?
CVE-2025-24434 affects Adobe Commerce versions up to 2.4.7 and several earlier versions.
What type of vulnerability is CVE-2025-24434?
CVE-2025-24434 is classified as an Improper Authorization vulnerability.
What can an attacker do by exploiting CVE-2025-24434?
By exploiting CVE-2025-24434, an attacker could bypass security measures and gain unauthorized access to the system.