Incorrect Authorization Flaw in Adobe Commerce Products
CVE-2025-54267
6.5MEDIUM
What is CVE-2025-54267?
Adobe Commerce is susceptible to an Incorrect Authorization vulnerability that enables low-privileged attackers to bypass security controls. This weakness allows unauthorized access to elevated privileges, posing a significant threat to the integrity of affected products. Notably, exploitation of this flaw does not require user interaction, thus increasing the risk of unauthorized actions within the system. Businesses using affected versions should prioritize reviewing their security configurations and applying necessary patches to mitigate potential exploitation.
Affected Version(s)
Adobe Commerce 0 <= 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved