Incorrect Authorization Vulnerability in Adobe Commerce Products
CVE-2025-49550

4.3MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
25 June 2025

What is CVE-2025-49550?

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, and 2.4.4-p13 are vulnerable to an Incorrect Authorization issue, allowing attackers to potentially bypass established security measures. Successful exploitation may grant unauthorized access with limited privileges, contingent upon user interaction to trigger the attack. It is crucial for users and administrators of affected versions to apply timely security patches and adhere to best practices for mitigating risks associated with this vulnerability.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49550 : Incorrect Authorization Vulnerability in Adobe Commerce Products