CVE-2025-24407
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Feb 11, 2025
Updated: Feb 27, 2025
CWE ID 863
Summary
CVE-2025-24407 is a newly disclosed vulnerability affecting Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, and earlier. This Incorrect Authorization issue enables unauthorized access, bypassing crucial security features. Attackers can exploit this vulnerability without user interaction to execute actions that are not granted to them, potentially leading to significant security risks. Adobe Commerce urges users to apply the available patches to mitigate this vulnerability promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Adobe Commerce
Affected Vendors
- Adobe