Incorrect Authorization Flaw in Adobe Commerce Products
CVE-2025-54267

6.5MEDIUM

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 October 2025

What is CVE-2025-54267?

Adobe Commerce is susceptible to an Incorrect Authorization vulnerability that enables low-privileged attackers to bypass security controls. This weakness allows unauthorized access to elevated privileges, posing a significant threat to the integrity of affected products. Notably, exploitation of this flaw does not require user interaction, thus increasing the risk of unauthorized actions within the system. Businesses using affected versions should prioritize reviewing their security configurations and applying necessary patches to mitigate potential exploitation.

Affected Version(s)

Adobe Commerce 0 <= 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54267 : Incorrect Authorization Flaw in Adobe Commerce Products