Improper Access Control in Adobe Commerce Products
CVE-2025-24424
6.5MEDIUM
What is CVE-2025-24424?
Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are vulnerable due to an improper access control issue. This flaw may allow a low-privileged attacker to bypass inherent security mechanisms without needing user interaction, potentially leading to unauthorized access. Organizations using affected versions should review security measures and apply appropriate updates to mitigate risks.
Affected Version(s)
Adobe Commerce 0 <= 2.4.8-beta1