Adobe Commerce | Improper Access Control (CWE-284)
Description
Adobe Commerce improper access control allows low-privileged authenticated users to bypass security measures, impacting integrity.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Adobe Commerce improper access control allows low-privileged authenticated users to bypass security measures, impacting integrity.
An Improper Access Control vulnerability exists in Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier [1]. The flaw stems from inadequate enforcement of access restrictions on certain backend operations, allowing authorized users with limited privileges to access resources or perform actions they should not be permitted to [1].
The vulnerability is exploitable by an authenticated user with low privileges, such as a store administrator with restricted roles. No user interaction is required beyond the attacker's own actions, meaning the attacker can trigger the bypass directly without tricking another user [1]. The attack surface is limited to authenticated sessions within the Adobe Commerce admin panel or API, requiring the attacker to already possess valid credentials [1].
Successful exploitation enables the attacker to bypass intended security controls, leading to a low impact on integrity. This could allow unauthorized modification of data, such as altering product details, prices, or other configuration settings that should be protected [1]. The confidentiality and availability of the system are not expected to be affected by this flaw [1].
Adobe has released security updates to address this vulnerability in the specified versions and later [1]. Users should apply the latest patches available from the official repository [2] or the Adobe Security Bulletin to mitigate the risk. No workarounds have been publicly documented, and the CVE is not currently listed in CISA's Known Exploited Vulnerabilities catalog.
- NVD - CVE-2024-45121
- GitHub - magento/magento2: Prior to making any Submission(s), you must sign an Adobe Contributor License Agreement, available here at: https://opensource.adobe.com/cla.html. All Submissions you make to Adobe Inc. and its affiliates, assigns and subsidiaries (collectively “Adobe”) are subject to the terms of the Adobe Contributor License Agreement.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
magento/community-editionPackagist | >= 2.4.7-beta1, < 2.4.7-p3 | 2.4.7-p3 |
magento/community-editionPackagist | >= 2.4.6-p1, < 2.4.6-p8 | 2.4.6-p8 |
magento/community-editionPackagist | >= 2.4.5-p1, < 2.4.5-p10 | 2.4.5-p10 |
magento/community-editionPackagist | < 2.4.4-p11 | 2.4.4-p11 |
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-2qhq-fw98-h6wgghsaADVISORY
- helpx.adobe.com/security/products/magento/apsb24-73.htmlghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-45121ghsaADVISORY
News mentions
0No linked articles in our index yet.