Published Feb 11, 2025.
Improper authorization (CVE-2025-24434) that lets a low-privileged actor escalate privileges; Adobe rated it critical because exploitation does not require user interaction. Fixed in the February 2025 patch set.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2025-24434 | 8.8 | improper-authorization | privilege-escalation | — |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB25-08
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →