Impact
Adobe Commerce versions 2.4.4‑p16 through 2.4.9‑alpha3 contain an Improper Input Validation flaw that allows an attacker to supply crafted data to bypass a security feature. The flaw is classified as CWE‑20 and results in a limited integrity impact, as it permits modification of application data or related state without providing elevated privileges or full control.
Affected Systems
Affecting Adobe Commerce and its B2B extension, the vulnerability covers release streams 2.4.4‑p16 and all earlier versions, 2.4.5‑p15, 2.4.6‑p13, 2.4.7‑p8, 2.4.8‑p3 and 2.4.9‑alpha3 across both community and enterprise editions.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates medium severity, while the EPSS score of less than 1% signifies a low likelihood of widespread exploitation. The flaw does not require user interaction, meaning an automated attacker can send crafted requests over the network to achieve the bypass, but it is not listed in the CISA KEV catalog.
OpenCVE Enrichment