Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue does not require user interaction.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Jun 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of this issue does not require user interaction. | |
Title | Adobe Commerce | Incorrect Authorization (CWE-863) | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published: 2025-06-25T17:41:13.652Z
Updated: 2025-06-25T18:12:41.002Z
Reserved: 2025-06-06T15:42:09.516Z
Link: CVE-2025-49549

Updated: 2025-06-25T18:12:31.390Z

Status : Awaiting Analysis
Published: 2025-06-25T18:15:22.163
Modified: 2025-06-26T18:57:43.670
Link: CVE-2025-49549

No data.