Improper Access Control in Adobe Commerce Affects Multiple Versions
CVE-2025-27206
5.3MEDIUM
What is CVE-2025-27206?
Adobe Commerce has been identified with an improper access control vulnerability that facilitates a security feature bypass. This flaw enables attackers to circumvent established security measures, granting them the ability to gain limited write access without requiring any user interaction. The affected versions include Adobe Commerce 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, and 2.4.4-p13, along with any prior versions. Organizations using these versions should review security practices and apply necessary mitigation strategies to safeguard their applications.
Affected Version(s)
Adobe Commerce 0 <= 2.4.4-p13