Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass

Vulnerability

A vulnerability allowing incorrect authorization has been identified in Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier. This vulnerability could lead to a security feature bypass, allowing a low privileged attacker to perform actions beyond their granted permissions. Such exploitation could result in a high impact on confidentiality and a low impact on integrity. Notably, this vulnerability can be exploited without user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed with elevated permissions, bypassing security features and potentially compromising sensitive information.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
3.1
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.