First published: Tue Apr 08 2025(Updated: )
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Magento Commerce | <2.4.8-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27191 is categorized as a security feature bypass vulnerability in Adobe Commerce.
To mitigate CVE-2025-27191, update to the latest version of Adobe Commerce beyond 2.4.8-beta2.
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, and 2.4.8-beta2 and earlier are affected by CVE-2025-27191.
An attacker could exploit CVE-2025-27191 to bypass security measures and gain unauthorized access to sensitive information.
CVE-2025-27191 was identified as a vulnerability within Adobe Commerce software.