CVE-2025-27206
Last modified
CVE-2025-27206 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this issue does not require user interaction.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Commerce | 2.4.4 |
| Adobe | Commerce | 2.4.5 |
| Adobe | Commerce | 2.4.6 |
| Adobe | Commerce | 2.4.7 |
| Adobe | Commerce | 2.4.8 |
| Adobe | Commerce B2b | 1.3.3 |
| Adobe | Commerce B2b | 1.3.4 |
| Adobe | Commerce B2b | 1.3.5 |
| Adobe | Commerce B2b | 1.4.2 |
| Adobe | Commerce B2b | 1.5.2 |
| Adobe | Magento | 2.4.5 |
| Adobe | Magento | 2.4.6 |
| Adobe | Magento | 2.4.7 |
| Adobe | Magento | 2.4.8 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27206?
How severe is CVE-2025-27206?
How do I fix CVE-2025-27206?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27200Animate versions 24.0.7, 23.0.10 and earlier are affected by…7.8
- CVE-2025-27201Animate versions 24.0.7, 23.0.10 and earlier are affected by…5.5
- CVE-2025-27202Animate versions 24.0.7, 23.0.10 and earlier are affected by…5.5
- CVE-2025-27203Adobe Connect versions 24.0 and earlier are affected by a De…9.6
- CVE-2025-27204After Effects versions 25.1, 24.6.4 and earlier are affected…5.5
- CVE-2025-27205Adobe Experience Manager Screens versions FP11.3 and earlier…5.4
- CVE-2025-27207Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p1…6.5
- CVE-2025-27208A reflected Cross-Site Scripting (XSS) vulnerability has bee…6.1
- CVE-2025-27209The V8 release used in Node.js v24.0.0 has changed how strin…7.5
- CVE-2025-2721Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2025-27210An incomplete fix has been identified for CVE-2025-23084 in …7.5
- CVE-2025-27211An Improper Input Validation in EdgeMAX EdgeSwitch (Version …7.5
Are you affected by CVE-2025-27206?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
