Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2025-27207

Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.

  • Published: Jun 10, 2025
  • Updated: Jun 11, 2025
  • CVE: CVE-2025-27207
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Software From Fixed in
adobe / commerce_b2b 1.4.2-p1 1.4.2-p1.x
adobe / commerce_b2b 1.4.2-p2 1.4.2-p2.x
adobe / commerce_b2b 1.4.2 1.4.2.x
adobe / commerce_b2b 1.3.5-p7 1.3.5-p7.x
adobe / commerce_b2b 1.3.4-p9 1.3.4-p9.x
adobe / commerce_b2b 1.3.4 1.3.4.x
adobe / commerce_b2b 1.3.3 1.3.3.x
adobe / commerce_b2b 1.3.3-p10 1.3.3-p10.x
adobe / commerce_b2b 1.3.3-p11 1.3.3-p11.x
adobe / commerce_b2b 1.3.3-p12 1.3.3-p12.x
adobe / commerce_b2b 1.3.3-p13 1.3.3-p13.x
adobe / commerce_b2b 1.3.4-p10 1.3.4-p10.x
adobe / commerce_b2b 1.3.4-p11 1.3.4-p11.x
adobe / commerce_b2b 1.3.5 1.3.5.x
adobe / commerce_b2b 1.3.5-p8 1.3.5-p8.x
adobe / commerce_b2b 1.3.5-p9 1.3.5-p9.x
adobe / commerce_b2b 1.4.2-p3 1.4.2-p3.x
adobe / commerce_b2b 1.4.2-p4 1.4.2-p4.x
adobe / commerce_b2b 1.3.4-p12 1.3.4-p12.x
adobe / commerce_b2b 1.3.5-p10 1.3.5-p10.x
adobe / commerce_b2b 1.4.2-p5 1.4.2-p5.x
adobe / commerce_b2b 1.5.2 1.5.2.x