cbcvebase.
CVE-2025-49558
published 2025-08-12

CVE-2025-49558: Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race…

medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by manipulating the timing between the check of a resource's state and its use, allowing unauthorized write access. Exploitation of this issue does not require user interaction.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
adobeadobe_commerce<= 2.4.4-p14
adobecommerce< 2.4.42.4.4
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce
adobecommerce_b2b< 1.3.31.3.3
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobecommerce_b2b
adobemagento< 2.4.52.4.5
adobemagento
adobemagento
adobemagento
adobemagento
adobemagento
magentocommunity-edition>= 0 < 2.4.5-p142.4.5-p14
magentocommunity-edition>= 2.4.6-p1 < 2.4.6-p122.4.6-p12
magentocommunity-edition>= 2.4.7-beta1 < 2.4.7-p72.4.7-p7
magentocommunity-edition>= 2.4.8-beta1 < 2.4.8-p22.4.8-p2
magentocommunity-edition>= 2.4.9-alpha1 < 2.4.9-alpha22.4.9-alpha2