Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9-alpha3
- <= 2.4.8-p3
- <= 2.4.7-p8
- <= 2.4.6-p13
- <= 2.4.5-p15
- <= 2.4.4-p16
A vulnerability allowing incorrect authorization has been identified in Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier. This vulnerability could lead to a security feature bypass, allowing attackers to circumvent security measures with limited impact on data integrity and availability. The exploitation of this vulnerability depends on conditions beyond the attacker's control and does not require user interaction.
Exploitation of this vulnerability could result in a security feature bypass, allowing attackers to circumvent certain security measures within the application.
Users are advised to update to Adobe Commerce 2.4.9‑beta1, 2.4.8‑p4, 2.4.7‑p9, 2.4.6‑p14, 2.4.5‑p16 or 2.4.4‑p17. For detailed installation instructions, refer to the Adobe Commerce release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.