Improper Access Control in Adobe Commerce Affects Multiple Versions
CVE-2025-27206

5.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
10 June 2025

What is CVE-2025-27206?

Adobe Commerce has been identified with an improper access control vulnerability that facilitates a security feature bypass. This flaw enables attackers to circumvent established security measures, granting them the ability to gain limited write access without requiring any user interaction. The affected versions include Adobe Commerce 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, and 2.4.4-p13, along with any prior versions. Organizations using these versions should review security practices and apply necessary mitigation strategies to safeguard their applications.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27206 : Improper Access Control in Adobe Commerce Affects Multiple Versions