CVE-2025-27191: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27191?
CVE-2025-27191 is categorized as a security feature bypass vulnerability in Adobe Commerce.
How do I fix CVE-2025-27191?
To mitigate CVE-2025-27191, update to the latest version of Adobe Commerce beyond 2.4.8-beta2.
What versions of Adobe Commerce are affected by CVE-2025-27191?
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, and 2.4.8-beta2 and earlier are affected by CVE-2025-27191.
What are the potential impacts of CVE-2025-27191?
An attacker could exploit CVE-2025-27191 to bypass security measures and gain unauthorized access to sensitive information.
Who discovered CVE-2025-27191?
CVE-2025-27191 was identified as a vulnerability within Adobe Commerce software.