Impact
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier contain an Incorrect Authorization flaw (CWE-863) that allows a low-privileged attacker to bypass security controls and gain limited unauthorized access to a protected feature. The vulnerability does not require user interaction.
Affected Systems
Affected products are Adobe Commerce (Magento) for all releases from 2.4.9-alpha3 back through 2.4.4-p16, including both the enterprise Commerce edition and the open‑source Magento editions that share the same underlying code base.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate level of severity, while the EPSS score of less than 1% shows that the likelihood of active exploitation is low. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. A low‑privileged attacker can exploit the issue without needing user interaction, enabling a security feature bypass.
OpenCVE Enrichment