VYPR
High severityNVD Advisory· Published Oct 10, 2024· Updated Oct 10, 2024

Adobe Commerce | Improper Access Control (CWE-284)

CVE-2024-45118

Description

CVE-2024-45118 is an improper access control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures, impacting integrity.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2024-45118 is an improper access control vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures, impacting integrity.

CVE-2024-45118 is an Improper Access Control vulnerability affecting Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10, and earlier. The root cause is a failure to properly enforce access controls, which allows a low-privileged attacker to bypass intended security restrictions without requiring user interaction [1].

An attacker with low privileges can exploit this vulnerability by sending crafted requests to the affected application, circumventing the access control checks that would normally prevent unauthorized actions. The attack does not require any special network position or user interaction, making it easier to execute [1].

Successful exploitation could lead to a high impact on integrity, meaning the attacker could potentially modify data or settings that should be protected. This bypass of security measures undermines the application's access control model and could enable further abuse of privileged functionality [1].

Adobe has addressed this vulnerability in security updates for the affected versions. Users are strongly advised to upgrade to the latest patched releases. The vulnerability has been publicly disclosed, but no evidence of active exploitation in the wild has been reported at the time of publication [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
magento/community-editionPackagist
>= 2.4.7-beta1, < 2.4.7-p32.4.7-p3
magento/community-editionPackagist
>= 2.4.6-p1, < 2.4.6-p82.4.6-p8
magento/community-editionPackagist
>= 2.4.5-p1, < 2.4.5-p102.4.5-p10
magento/community-editionPackagist
< 2.4.4-p112.4.4-p11

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.