CVE-2025-43586: Adobe Commerce | Improper Access Control (CWE-284)
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43586?
CVE-2025-43586 is classified as a low-severity vulnerability affecting Adobe Commerce that could lead to privilege escalation.
How do I fix CVE-2025-43586?
The recommended fix for CVE-2025-43586 is to update Adobe Commerce to the latest secure version released by Adobe.
What versions of Adobe Commerce are affected by CVE-2025-43586?
CVE-2025-43586 affects Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier.
What type of attack can exploit CVE-2025-43586?
CVE-2025-43586 can be exploited by a low privileged attacker to bypass security measures and perform unauthorized actions.
Is there a patch available for CVE-2025-43586?
Yes, Adobe has released a patch as part of their newer versions to address the security vulnerabilities identified in CVE-2025-43586.