CVE-2025-54263: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and maintain unauthorized access. Exploitation of this issue does not require user interaction.
Other sources
Magento versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and maintain unauthorized access. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54263?
CVE-2025-54263 is categorized as a low-severity vulnerability.
How do I fix CVE-2025-54263?
To remediate CVE-2025-54263, update Adobe Commerce to version 2.4.9 or later.
Who is affected by CVE-2025-54263?
CVE-2025-54263 affects Adobe Commerce versions 2.4.9-alpha2 and earlier.
What type of vulnerability is CVE-2025-54263?
CVE-2025-54263 is classified as an Incorrect Authorization vulnerability.
What could an attacker do with CVE-2025-54263?
An attacker could leverage CVE-2025-54263 to bypass security measures and maintain unauthorized access.