CVE-2025-24434
published 2025-02-11CVE-2025-24434: Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could…
PriorityP274critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
16.50%
96.6th percentile
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.8-beta1 | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| magento | community-edition | >= 0 < 2.4.4-p12 | 2.4.4-p12 |
| magento | community-edition | >= 2.4.5-p1 < 2.4.5-p11 | 2.4.5-p11 |
| magento | community-edition | >= 2.4.6-p1 < 2.4.6-p9 | 2.4.6-p9 |
| magento | community-edition | >= 2.4.7-beta1 < 2.4.7-p4 | 2.4.7-p4 |
| magento | community-edition | >= 2.4.8-beta1 < 2.4.8-beta2 | 2.4.8-beta2 |
| magento | project-community-edition | 0 – 2.0.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-24434 is an improper/incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that allows unauthenticated attackers to escalate privileges without user interaction, potentially leading to session takeover and remote code execution. ↗
- →Exploitation does not require user interaction and can result in session takeover; monitor Adobe Commerce/Magento for unauthorized privilege escalation and unexpected session activity. ↗
- ·Affected versions include Adobe Commerce 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier; apply Adobe's isolated patches promptly. ↗
- ·Affected users are advised to apply the isolated patches provided by Adobe promptly to remediate CVE-2025-24434. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authorization vulnerability in Magento and Adobe Commerce
osv·2025-02-11
CVE-2025-24434 [CRITICAL] Improper Authorization vulnerability in Magento and Adobe Commerce
Improper Authorization vulnerability in Magento and Adobe Commerce
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
GHSA
Improper Authorization vulnerability in Magento and Adobe Commerce
ghsa·2025-02-11
CVE-2025-24434 [CRITICAL] CWE-285 Improper Authorization vulnerability in Magento and Adobe Commerce
Improper Authorization vulnerability in Magento and Adobe Commerce
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
No detection rules found.
No public exploits indexed.
2025-02-11
Published