CVE-2025-27191

MEDIUM

Adobe Commerce <2.4.8-beta2 - Privilege Escalation

Title source: llm

Description

Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.

Scores

CVSS v3 5.3
EPSS 0.0084
EPSS Percentile 74.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-284
Status published

Affected Products (50)

adobe/commerce < 2.4.4
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
... and 35 more

Timeline

Published Apr 08, 2025
Tracked Since Feb 18, 2026