CVE-2025-24435: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify limited fields. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify limited fields. Exploitation of this issue does not require user interaction.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24435?
The severity of CVE-2025-24435 is categorized as a low severity due to its improper access control nature.
How do I fix CVE-2025-24435?
To fix CVE-2025-24435, update your Adobe Commerce installation to a version later than 2.4.7-beta1.
Who is affected by CVE-2025-24435?
CVE-2025-24435 affects Adobe Commerce versions up to and including 2.4.7-beta1.
What type of vulnerability is CVE-2025-24435?
CVE-2025-24435 is an Improper Access Control vulnerability that may lead to privilege escalation.
Can a low-privileged attacker exploit CVE-2025-24435?
Yes, a low-privileged attacker can exploit CVE-2025-24435 to bypass security measures and gain elevated privileges.