Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
The error results from improper input validation in Adobe Commerce. An attacker, without possessing an account or requiring any user interaction, can supply crafted input data to the vulnerable application mechanism. This results in hijacking an active session of another user — potentially including store administrators — giving the attacker high-level access to sensitive data and the ability to modify resources.
An attacker can gain full control over a hijacked session, resulting in high impact on confidentiality (access to customer data, orders, configuration) and system integrity (ability to introduce unauthorized changes). The vulnerability does not directly affect system availability.
Adobe Commerce and Magento must be immediately updated to versions containing the patch described in the vendor security bulletin APSB25-88 (https://helpx.adobe.com/security/products/magento/apsb25-88.html). Due to active exploitation in production environments, the update should be an immediate priority. Until the patch is deployed, enhanced session monitoring is recommended and restricting access to the administrative panel should be considered.
Adobe Commerce and Adobe Magento in versions: 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier. Also affects Adobe Commerce B2B.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NAdobe Commerce
APPAdobe2.4.42.4.52.4.62.4.72.4.82.4.9Adobe Commerce B2b
APPAdobe1.3.31.3.41.4.21.5.21.5.3Adobe Magento
APPAdobe2.4.52.4.62.4.72.4.82.4.9
CISA KEV — detailsi
- Vendori
- Adobe ↗
- Producti
- Commerce and Magento
- Added to KEVi
- October 24, 2025
- Remediation deadline (US Federal)i
- November 14, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
Related vulnerabilities
Krytyczna podatność XXE w Adobe Commerce umożliwiająca RCE
Adobe Commerce — RCE przez błędną walidację danych podczas checkout
Adobe Commerce — nieograniczony upload pliku umożliwiający RCE
RCE w Adobe Commerce — błąd kodowania wyjścia (CVE-2026-48358)
Adobe Commerce — Incorrect Authorization umożliwiające privilege escalation