Missing authorization in Adobe products - CVE-2025-43585
Published: June 10, 2025
Vulnerability identifier: #VU111021
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43585
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to missing authorization checks. A remote non-authenticated attacker can send a specially crafted HTTP request and read or modify data within the application.
Affected software
Adobe Commerce B2B
Adobe Commerce (formerly Magento Commerce)
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
Magento Open Source
How to mitigate CVE-2025-43585
Install updates from vendor's website.
Adobe Commerce B2B - addressed in versions 1.3.3-p14, 1.3.4-p13, 1.4.2-p6, 1.5.2-p1, 1.5.3 alpha1
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4-p14, 2.4.5-p13, 2.4.6-p11, 2.4.7-p6, 2.4.8-p1, 2.4.9 alpha1
Magento Open Source - addressed in versions 2.4.5-p13, 2.4.6-p11, 2.4.7-p6, 2.4.8-p1, 2.4.9 alpha1
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4-p14, 2.4.5-p13, 2.4.6-p11, 2.4.7-p6, 2.4.8-p1, 2.4.9 alpha1
Magento Open Source - addressed in versions 2.4.5-p13, 2.4.6-p11, 2.4.7-p6, 2.4.8-p1, 2.4.9 alpha1