CVE-2025-49556

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction, and scope is unchanged.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
adobeCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
adobecommerce
𝑥
< 2.4.4
adobecommerce
2.4.4
adobecommerce
2.4.4:p1
adobecommerce
2.4.4:p10
adobecommerce
2.4.4:p11
adobecommerce
2.4.4:p12
adobecommerce
2.4.4:p13
adobecommerce
2.4.4:p14
adobecommerce
2.4.4:p2
adobecommerce
2.4.4:p3
adobecommerce
2.4.4:p4
adobecommerce
2.4.4:p5
adobecommerce
2.4.4:p6
adobecommerce
2.4.4:p7
adobecommerce
2.4.4:p8
adobecommerce
2.4.4:p9
adobecommerce
2.4.5
adobecommerce
2.4.5:p1
adobecommerce
2.4.5:p10
adobecommerce
2.4.5:p11
adobecommerce
2.4.5:p12
adobecommerce
2.4.5:p13
adobecommerce
2.4.5:p2
adobecommerce
2.4.5:p3
adobecommerce
2.4.5:p4
adobecommerce
2.4.5:p5
adobecommerce
2.4.5:p6
adobecommerce
2.4.5:p7
adobecommerce
2.4.5:p8
adobecommerce
2.4.5:p9
adobecommerce
2.4.6
adobecommerce
2.4.6:p1
adobecommerce
2.4.6:p10
adobecommerce
2.4.6:p11
adobecommerce
2.4.6:p2
adobecommerce
2.4.6:p3
adobecommerce
2.4.6:p4
adobecommerce
2.4.6:p5
adobecommerce
2.4.6:p6
adobecommerce
2.4.6:p7
adobecommerce
2.4.6:p8
adobecommerce
2.4.6:p9
adobecommerce
2.4.7
adobecommerce
2.4.7:b1
adobecommerce
2.4.7:b2
adobecommerce
2.4.7:beta3
adobecommerce
2.4.7:p1
adobecommerce
2.4.7:p2
adobecommerce
2.4.7:p3
adobecommerce
2.4.7:p4
adobecommerce
2.4.7:p5
adobecommerce
2.4.7:p6
adobecommerce
2.4.8
adobecommerce
2.4.8:beta1
adobecommerce_b2b
𝑥
< 1.3.3
adobecommerce_b2b
1.3.3
adobecommerce_b2b
1.3.3:p1
adobecommerce_b2b
1.3.3:p10
adobecommerce_b2b
1.3.3:p11
adobecommerce_b2b
1.3.3:p12
adobecommerce_b2b
1.3.3:p13
adobecommerce_b2b
1.3.3:p14
adobecommerce_b2b
1.3.3:p2
adobecommerce_b2b
1.3.3:p3
adobecommerce_b2b
1.3.3:p4
adobecommerce_b2b
1.3.3:p5
adobecommerce_b2b
1.3.3:p6
adobecommerce_b2b
1.3.3:p7
adobecommerce_b2b
1.3.3:p8
adobecommerce_b2b
1.3.3:p9
adobecommerce_b2b
1.3.4
adobecommerce_b2b
1.3.4:p1
adobecommerce_b2b
1.3.4:p10
adobecommerce_b2b
1.3.4:p11
adobecommerce_b2b
1.3.4:p12
adobecommerce_b2b
1.3.4:p13
adobecommerce_b2b
1.3.4:p2
adobecommerce_b2b
1.3.4:p3
adobecommerce_b2b
1.3.4:p4
adobecommerce_b2b
1.3.4:p5
adobecommerce_b2b
1.3.4:p6
adobecommerce_b2b
1.3.4:p7
adobecommerce_b2b
1.3.4:p8
adobecommerce_b2b
1.3.4:p9
adobecommerce_b2b
1.3.5
adobecommerce_b2b
1.3.5:p1
adobecommerce_b2b
1.3.5:p10
adobecommerce_b2b
1.3.5:p11
adobecommerce_b2b
1.3.5:p2
adobecommerce_b2b
1.3.5:p3
adobecommerce_b2b
1.3.5:p4
adobecommerce_b2b
1.3.5:p5
adobecommerce_b2b
1.3.5:p6
adobecommerce_b2b
1.3.5:p7
adobecommerce_b2b
1.3.5:p8
adobecommerce_b2b
1.3.5:p9
adobecommerce_b2b
1.4.2
adobecommerce_b2b
1.4.2:p1
adobecommerce_b2b
1.4.2:p2
adobecommerce_b2b
1.4.2:p3
adobecommerce_b2b
1.4.2:p4
adobecommerce_b2b
1.4.2:p5
adobecommerce_b2b
1.4.2:p6
adobecommerce_b2b
1.5.2
adobecommerce_b2b
1.5.2:p1
adobecommerce_b2b
1.5.3:alpha1
adobemagento
𝑥
< 2.4.5
adobemagento
2.4.5
adobemagento
2.4.5:p1
adobemagento
2.4.5:p10
adobemagento
2.4.5:p11
adobemagento
2.4.5:p12
adobemagento
2.4.5:p13
adobemagento
2.4.5:p2
adobemagento
2.4.5:p3
adobemagento
2.4.5:p4
adobemagento
2.4.5:p5
adobemagento
2.4.5:p6
adobemagento
2.4.5:p7
adobemagento
2.4.5:p8
adobemagento
2.4.5:p9
adobemagento
2.4.6
adobemagento
2.4.6:p1
adobemagento
2.4.6:p10
adobemagento
2.4.6:p11
adobemagento
2.4.6:p2
adobemagento
2.4.6:p3
adobemagento
2.4.6:p4
adobemagento
2.4.6:p5
adobemagento
2.4.6:p6
adobemagento
2.4.6:p7
adobemagento
2.4.6:p8
adobemagento
2.4.6:p9
adobemagento
2.4.7
adobemagento
2.4.7:b1
adobemagento
2.4.7:b2
adobemagento
2.4.7:beta3
adobemagento
2.4.7:p1
adobemagento
2.4.7:p2
adobemagento
2.4.7:p3
adobemagento
2.4.7:p4
adobemagento
2.4.7:p5
adobemagento
2.4.7:p6
adobemagento
2.4.8
adobemagento
2.4.8:beta1
adobemagento
2.4.8:beta2
adobemagento
2.4.8:p1
adobemagento
2.4.9:alpha1
𝑥
= Vulnerable software versions