CVE-2025-54236: Adobe Commerce and Magento Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Other sources
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
— GitHub
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Adobe Commerce or Magento Open Source if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54236?
CVE-2025-54236 is considered a high-severity vulnerability due to its potential for security feature bypass and session takeover.
How do I fix CVE-2025-54236?
To fix CVE-2025-54236, upgrade your Adobe Commerce installation to version 2.4.9-alpha3 or later, or apply any available security patches.
What versions of Adobe Commerce are affected by CVE-2025-54236?
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and 2.4.4-p15 and earlier are affected by CVE-2025-54236.
Can CVE-2025-54236 lead to data breaches?
Yes, CVE-2025-54236 can potentially lead to data breaches through session takeover if exploited by an attacker.
What can I do to protect against CVE-2025-54236?
To protect against CVE-2025-54236, ensure your Adobe Commerce software is updated to the latest version and monitor for suspicious activity.