Adobe Commerce Incorrect Authorization Vulnerability Allowing Security Feature Bypass

Vulnerability

An incorrect authorization vulnerability has been identified in Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, and 2.4.8-beta1 and earlier. This vulnerability could allow a low-privileged attacker to bypass security features and view or modify certain information, without requiring user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized access to information or the ability to make unauthorized modifications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
5.0
exploitability
5.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.