CVE-2025-27188: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Other sources
Magento versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27188?
CVE-2025-27188 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-27188?
To fix CVE-2025-27188, ensure that your Adobe Commerce installation is updated to a version later than 2.4.8-beta2.
What types of attacks can CVE-2025-27188 enable?
CVE-2025-27188 can enable attacks that result in privilege escalation, allowing unauthorized access to sensitive areas of the application.
Which software versions are affected by CVE-2025-27188?
CVE-2025-27188 affects Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, and 2.4.8-beta2 and earlier.
What should I do if I cannot immediately update my Adobe Commerce application due to CVE-2025-27188?
If immediate updates are not possible, implement comprehensive security measures to limit access and monitor for suspicious activity.