CVE-2025-49558: Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by manipulating the timing between the check of a resource's state and its use, allowing unauthorized write access. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49558?
CVE-2025-49558 is classified as a security feature bypass vulnerability affecting specific versions of Adobe Commerce.
How do I fix CVE-2025-49558?
To fix CVE-2025-49558, upgrade your Adobe Commerce version to the latest patched release that addresses the vulnerability.
What versions of Adobe Commerce are affected by CVE-2025-49558?
CVE-2025-49558 affects Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier.
What type of vulnerability is CVE-2025-49558?
CVE-2025-49558 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability.
What could an attacker achieve by exploiting CVE-2025-49558?
An attacker could exploit CVE-2025-49558 to bypass security features in the affected versions of Adobe Commerce.