CRITICAL

CVE-2025-54236

Adobe Commerce 2025-09-09 CVSS v3.1
CVSS
9.1
KEV

Description

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.

Summary dbcve.org

Adobe Commerce (Magento) contains an improper input validation vulnerability allowing unauthenticated attackers to achieve session takeover. The flaw affects versions 2.4.4-p15 through 2.4.9-alpha2 and enables complete compromise of user sessions without any user interaction, resulting in high confidentiality and integrity impact.

Mitigation

Apply the available Adobe Commerce security patch or upgrade to a fixed version (2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, or later) to remediate this vulnerability.

Proof of Concept

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

94.53%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE