Adobe Commerce | Improper Access Control (CWE-284)
Description
CVE-2024-45118 is an improper access control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures, impacting integrity.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2024-45118 is an improper access control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures, impacting integrity.
CVE-2024-45118 is an Improper Access Control vulnerability affecting Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10, and earlier. The root cause is a failure to properly enforce access controls, which allows a low-privileged attacker to bypass intended security restrictions without requiring user interaction [1].
An attacker with low privileges can exploit this vulnerability by sending crafted requests to the affected application, circumventing the access control checks that would normally prevent unauthorized actions. The attack does not require any special network position or user interaction, making it easier to execute [1].
Successful exploitation could lead to a high impact on integrity, meaning the attacker could potentially modify data or settings that should be protected. This bypass of security measures undermines the application's access control model and could enable further abuse of privileged functionality [1].
Adobe has addressed this vulnerability in security updates for the affected versions. Users are strongly advised to upgrade to the latest patched releases. The vulnerability has been publicly disclosed, but no evidence of active exploitation in the wild has been reported at the time of publication [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/community-editionPackagist | >= 2.4.7-beta1, < 2.4.7-p3 | 2.4.7-p3 |
magento/community-editionPackagist | >= 2.4.6-p1, < 2.4.6-p8 | 2.4.6-p8 |
magento/community-editionPackagist | >= 2.4.5-p1, < 2.4.5-p10 | 2.4.5-p10 |
magento/community-editionPackagist | < 2.4.4-p11 | 2.4.4-p11 |
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-cg52-68fv-94qqghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb24-73.htmlghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-45118ghsaADVISORY
News mentions
0No linked articles in our index yet.