CVE-2025-27190: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27190?
CVE-2025-27190 is rated as a critical vulnerability due to its potential for security feature bypass.
How do I fix CVE-2025-27190?
To mitigate CVE-2025-27190, upgrade Adobe Commerce to version 2.4.8 or later.
What are the affected versions for CVE-2025-27190?
CVE-2025-27190 affects Adobe Commerce versions up to 2.4.8-beta2.
Who can exploit CVE-2025-27190?
Any attacker with access to the affected system can potentially exploit CVE-2025-27190.
What is the impact of CVE-2025-27190?
CVE-2025-27190 can lead to unauthorized access and potential data manipulation or compromise.