CVE-2025-27192: Adobe Commerce | Insufficiently Protected Credentials (CWE-522)
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27192?
CVE-2025-27192 is classified as a high severity vulnerability due to its potential to allow security feature bypass by privileged attackers.
How do I fix CVE-2025-27192?
To fix CVE-2025-27192, it is recommended to upgrade to Adobe Commerce versions later than 2.4.8-beta2.
What does CVE-2025-27192 affect?
CVE-2025-27192 affects Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, and 2.4.8-beta2 and earlier.
What types of attacks can exploit CVE-2025-27192?
CVE-2025-27192 can be exploited by high privileged attackers to gain unauthorized access through security feature bypass.
When was CVE-2025-27192 disclosed?
The disclosure date for CVE-2025-27192 is not mentioned in the provided information.