CVE-2025-49556

HIGH

Adobe Commerce < 2.4.4 - Incorrect Authorization

Title source: rule

Description

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction, and scope is unchanged.

Scores

CVSS v3 7.5
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-863
Status published

Affected Products (50)

adobe/commerce < 2.4.4
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
adobe/commerce
... and 35 more

Timeline

Published Aug 12, 2025
Tracked Since Feb 18, 2026