High severity7.5NVD Advisory· Published Aug 16, 2022· Updated Jun 17, 2026
CVE-2022-34256
CVE-2022-34256
Description
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data. Exploitation of this issue does not require user interaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/community-editionPackagist | >= 2.3.0, < 2.3.7-p4 | 2.3.7-p4 |
magento/community-editionPackagist | >= 2.4.4, < 2.4.5 | 2.4.5 |
magento/community-editionPackagist | >= 2.4.0, < 2.4.3-p3 | 2.4.3-p3 |
Affected products
21cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*range: >=2.3.0,<2.3.7
- cpe:2.3:a:adobe:commerce:2.3.7:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.3.7:p1:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.3.7:p2:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.3.7:p3:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.3:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.3:p1:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.3:p2:*:*:*:*:*:*
- cpe:2.3:a:adobe:commerce:2.4.4:-:*:*:*:*:*:*
cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*+ 8 more
- cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*range: >=2.3.0,<2.3.7
- cpe:2.3:a:magento:magento:2.3.7:-:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.3.7:p1:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.3.7:p2:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.3.7:p3:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.4.3:-:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.4.3:p1:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.4.3:p2:*:*:commerce:*:*:*
- cpe:2.3:a:magento:magento:2.4.4:-:*:*:commerce:*:*:*
- osv-coords2 versions
>= 2.3.0, < 2.3.7+ 1 more
- (no CPE)range: >= 2.3.0, < 2.3.7
- (no CPE)range: >= 2.3.0, < 2.3.7-p4
- Range: unspecified
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-r7mm-grf3-5fjvghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb22-38.htmlnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-34256ghsaADVISORY
- github.com/magento/magento2/commit/246d524b7586af2245092008e0d92b8d6fdd8523ghsaWEB
- github.com/magento/magento2/commit/5548bc64b5bc904346c0af9193a7fbb5274b4efaghsaWEB
- github.com/magento/magento2/commit/5f07eba878296a37bd5c3a2baecad48948547594ghsaWEB
News mentions
0No linked articles in our index yet.