Adobe Commerce
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*
- <= 2.4.9
- <= 2.4.8-p5
- <= 2.4.7-p10
- <= 2.4.6-p15
- <= 2.4.5-p17
- <= 2.4.4-p18
A vulnerability allowing incorrect authorization has been identified in Adobe Commerce. This issue could lead to a security feature bypass, allowing unauthorized read and write access. The vulnerability is present in Adobe Commerce versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier. It also affects Adobe Commerce B2B versions 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier. Additionally, Magento Open Source versions 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, and 2.4.6-p15 and earlier are affected. The vulnerability exploitation does not require user interaction.
Exploitation of this vulnerability could bypass security features, allowing unauthorized access to read and write data.
Users are advised to update to the latest versions of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source. Instructions for updating can be found in the Adobe Security Bulletin APSB26-73.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.