Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality and integrity impact as high.
The vulnerability results from improper authorization verification in Adobe Commerce. An attacker can remotely bypass access control mechanisms without needing to own an account or engage the victim. After successfully exploiting the flaw, it is possible to hijack another user's session (session takeover), which translates to gaining full control over their account and data.
An attacker can gain unauthorized access to other users' accounts by hijacking their sessions, resulting in a breach of confidentiality and data integrity within the Adobe Commerce platform.
Apply patches available from the vendor according to references: https://helpx.adobe.com/security/products/magento/apsb25-08.html
Adobe Commerce in versions: 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NAdobe Commerce
APPAdobe2.4.42.4.52.4.62.4.72.4.8Adobe Commerce B2b
APPAdobe1.3.31.3.41.3.51.4.21.5.0Adobe Magento
APPAdobe2.4.42.4.52.4.62.4.72.4.8
Related vulnerabilities
Adobe Commerce/Magento — przejęcie sesji przez Improper Input Validation
Krytyczna podatność XXE w Adobe Commerce umożliwiająca RCE
Adobe Commerce — RCE przez błędną walidację danych podczas checkout
Adobe Commerce — nieograniczony upload pliku umożliwiający RCE
RCE w Adobe Commerce — błąd kodowania wyjścia (CVE-2026-48358)