CVE-2025-54265: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Other sources
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
— NVD
Magento versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54265?
CVE-2025-54265 has been classified as a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-54265?
To remediate CVE-2025-54265, update Adobe Commerce to version 2.4.9 or later immediately.
What versions of Adobe Commerce are affected by CVE-2025-54265?
Affected versions include Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and 2.4.4-p15.
What type of vulnerability is CVE-2025-54265?
CVE-2025-54265 is an Incorrect Authorization vulnerability allowing unauthorized read access.
What can happen if CVE-2025-54265 is exploited?
Exploitation of CVE-2025-54265 can lead to attackers bypassing security measures and gaining unauthorized access to sensitive data.