CVE-2025-54236: Adobe Commerce and Magento Improper Input Validation Vulnerability
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Other sources
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact to high. Exploitation of this issue does not require user interaction.
— GitHub
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
composer/magento/community-editionfrom your environment.Discontinue use of the product or uninstall if vendor mitigations are unavailable for the Improper Input Validation vulnerability.
- Remove
Remove
composer/magento/project-community-editionfrom your environment.Discontinue use of the product or uninstall if vendor mitigations are unavailable for the Improper Input Validation vulnerability.
- Compensating control
Apply mitigations per vendor instructions for the Improper Input Validation vulnerability. Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54236?
CVE-2025-54236 is considered a high-severity vulnerability due to its potential for security feature bypass and session takeover.
How do I fix CVE-2025-54236?
To fix CVE-2025-54236, upgrade your Adobe Commerce installation to version 2.4.9-alpha3 or later, or apply any available security patches.
What versions of Adobe Commerce are affected by CVE-2025-54236?
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and 2.4.4-p15 and earlier are affected by CVE-2025-54236.
Can CVE-2025-54236 lead to data breaches?
Yes, CVE-2025-54236 can potentially lead to data breaches through session takeover if exploited by an attacker.
What can I do to protect against CVE-2025-54236?
To protect against CVE-2025-54236, ensure your Adobe Commerce software is updated to the latest version and monitor for suspicious activity.