Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-24434


Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.


Published

2025-02-11T18:15:46.157

Last Modified

2025-04-16T14:22:46.843

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-863
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.4 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.5 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.6 Yes
Application adobe commerce 2.4.7 Yes
Application adobe commerce 2.4.7 Yes
Application adobe commerce 2.4.7 Yes
Application adobe commerce 2.4.7 Yes
Application adobe commerce 2.4.8 Yes
Application adobe commerce_b2b 1.3.3 Yes
Application adobe commerce_b2b 1.3.3 Yes
Application adobe commerce_b2b 1.3.3 Yes
Application adobe commerce_b2b 1.3.4 Yes
Application adobe commerce_b2b 1.3.4 Yes
Application adobe commerce_b2b 1.3.4 Yes
Application adobe commerce_b2b 1.3.5 Yes
Application adobe commerce_b2b 1.3.5 Yes
Application adobe commerce_b2b 1.3.5 Yes
Application adobe commerce_b2b 1.4.2 Yes
Application adobe commerce_b2b 1.4.2 Yes
Application adobe commerce_b2b 1.4.2 Yes
Application adobe commerce_b2b 1.4.2 Yes
Application adobe commerce_b2b 1.5.0 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.4 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.5 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.6 Yes
Application adobe magento 2.4.7 Yes
Application adobe magento 2.4.7 Yes
Application adobe magento 2.4.7 Yes
Application adobe magento 2.4.7 Yes
Application adobe magento 2.4.8 Yes

References