CVE-2025-24436: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of this issue does not require user interaction.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID CVE-2025-24436?
CVE-2025-24436 is an Improper Access Control vulnerability in Adobe Commerce that can lead to privilege escalation.
What versions of software are affected by CVE-2025-24436?
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by CVE-2025-24436.
How do I fix CVE-2025-24436?
To fix CVE-2025-24436, update Adobe Commerce to a version later than 2.4.7-beta1.
What are the potential impacts of CVE-2025-24436?
CVE-2025-24436 allows attackers to bypass security measures, resulting in unauthorized access and privilege escalation.
Who are the vendors for CVE-2025-24436?
The vendor for CVE-2025-24436 is Adobe, specifically for their product Adobe Commerce.