Adobe Commerce TOCTOU Race Condition Vulnerability Allowing Security Feature Bypass

Vulnerability

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability has been identified in Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier. This vulnerability could lead to a bypass of security features by allowing an attacker to exploit the race condition to change a condition after it has been verified but before it is applied, potentially circumventing rate limiting measures. The exploitation of this vulnerability does not require user interaction.

Impact

Exploitation of this vulnerability could bypass security features, particularly rate limiting mechanisms, allowing for potentially abusive behavior without detection.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.