CVE-2025-54236criticalunder attackCWE-20

CVE-2025-54236: critical vulnerability in Adobe Commerce

Adobe Commerce | Improper Input Validation (CWE-20)

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.1epss 95%
from disclosure to weapon1 days
Published on NVDSep 9
1st PoC+1d
metasploit+43d
CISA KEV+45d
exploitation probability
95%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
12 public exploit(s)
Action required by CISAfederal deadline: 2025-11-14

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

Adobe Commerce has a flaw that fails to properly check user input, allowing attackers to take over customer or admin sessions without any user action. This gives attackers full access to accounts and sensitive data.

Technical detail

Improper input validation in affected Adobe Commerce versions (2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier) enables unauthenticated session hijacking. The vulnerability allows attackers to craft malicious input that bypasses validation controls, leading to unauthorized session establishment without requiring user interaction, resulting in high confidentiality and integrity impact.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Adobe · Adobe Commerce
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.