Adobe Commerce Incorrect Authorization Vulnerability

MEDIUM (6.5) No Patch (67 days)

Threat Intelligence

Medium Risk - Detectable
EPSS Score: 0.06% chance of exploitation (percentile: 19%)
🔍 Detection Tools: OSV.dev
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Adobe Commerce is an e-commerce platform used by many businesses to manage online stores. This vulnerability allows a low-privileged attacker to bypass security measures and gain unauthorized access to elevated privileges, increasing the integrity impact to high.

Am I affected?

You're affected if you use Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and earlier. To check if your version is affected, run the following command: osv.dev/Trivy (package scanner) or use a similar tool to scan for Adobe Commerce packages.

Note: This vulnerability does not affect Adobe Commerce Cloud versions, as they are isolated from on-premises environments.

Affected Products

Adobe Inc. / Adobe Commerce

How to fix

To fix this issue, upgrade to Adobe Commerce version 2.5.0-ga or later. If an immediate upgrade isn't possible:

  1. Restrict network access to your Adobe Commerce instance (firewall it from the public internet).
  2. Audit admin account activity for suspicious access patterns.
  3. Monitor for unauthorized token creation.

For more information on upgrading, refer to the official Adobe documentation: https://helpx.adobe.com/security/products/magento/apsb25-94.html

References