Improper Access Control in Adobe Commerce Affects Multiple Versions
CVE-2025-27206
What is CVE-2025-27206?
Adobe Commerce has been identified with an improper access control vulnerability that facilitates a security feature bypass. This flaw enables attackers to circumvent established security measures, granting them the ability to gain limited write access without requiring any user interaction. The affected versions include Adobe Commerce 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, and 2.4.4-p13, along with any prior versions. Organizations using these versions should review security practices and apply necessary mitigation strategies to safeguard their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Adobe Commerce 0 <= 2.4.4-p13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved