Incorrect Authorization Flaw in Adobe Commerce Products
CVE-2025-54267
What is CVE-2025-54267?
Adobe Commerce is susceptible to an Incorrect Authorization vulnerability that enables low-privileged attackers to bypass security controls. This weakness allows unauthorized access to elevated privileges, posing a significant threat to the integrity of affected products. Notably, exploitation of this flaw does not require user interaction, thus increasing the risk of unauthorized actions within the system. Businesses using affected versions should prioritize reviewing their security configurations and applying necessary patches to mitigate potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved