CVE-2025-54267: Adobe Commerce | Incorrect Authorization (CWE-863)
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to elevated privileges that increase integrity impact to high. Exploitation of this issue does not require user interaction.
Other sources
Magento versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to elevated privileges that increase integrity impact to high. Exploitation of this issue does not require user interaction.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54267?
CVE-2025-54267 has been classified as a low severity vulnerability.
How do I fix CVE-2025-54267?
To fix CVE-2025-54267, upgrade Adobe Commerce to versions later than 2.4.9-alpha2.
What kind of attack can exploit CVE-2025-54267?
CVE-2025-54267 can be exploited by low-privileged attackers to bypass authorization controls.
Which Adobe Commerce versions are affected by CVE-2025-54267?
CVE-2025-54267 affects Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier.
What is the nature of the vulnerability in CVE-2025-54267?
CVE-2025-54267 is an Incorrect Authorization vulnerability allowing unauthorized access.