Session Management Vulnerability in Optimizely Configured Commerce
CVE-2025-22386

Currently unrated

Key Information:

Vendor

Optimizely

Vendor
CVE Published:
4 January 2025

What is CVE-2025-22386?

A session management issue has been identified in Optimizely Configured Commerce prior to version 5.2.2408, particularly affecting its B2B application. This vulnerability allows session tokens tied to logged-out users to remain active in the storefront. As a result, unauthorized users could exploit these active session tokens, potentially leading to unauthorized access and manipulation of sensitive data within the application. Organizations using affected versions are strongly advised to apply the necessary updates to safeguard their systems and maintain session security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.