Description
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.
Related CPE's
a
adobe
commerce
42
a
adobe
commerce_b2b
20
a
adobe
magento
43
References
https://helpx.adobe.com/security/products/magento/apsb25-26.html
PatchRelease NotesVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2025-04-08T21:15:50.393Z
1 year agoLast modified
2026-06-17T09:03:10.403Z
3 months ago