Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a critical security flaw. An attacker can exploit this vulnerability to take over customer accounts without needing any user interaction or login credentials. This could lead to the theft of sensitive customer data and unauthorized access to shopping accounts, potentially damaging business reputation and customer trust.
Technical details
An improper input validation vulnerability (CWE-20) exists in Adobe Commerce and Magento Open Source within the Commerce REST API. The flaw allows a remote, unauthenticated attacker to bypass security checks and achieve session takeover. Exploitation does not require user interaction and has a high impact on confidentiality and integrity. This vulnerability is confirmed to be exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patches are available in updated versions including 2.4.8-p2, 2.4.7-p7, and other listed maintenance releases.
Affected products
- Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
- Adobe Magento Open Source 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
Timeline
- 2025-10-24: advisory: Adobe published security advisory APSB25-88
- 2025-10-24: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog
- 2025-10-24: exploited: Vulnerability reported as being exploited in the wild