Published Apr 8, 2025.
Improper authorization (CVE-2025-27189) allowing a security feature bypass, published alongside the 2.4.8 general availability release. Older lines receive the fix through their April 2025 patch versions.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2025-27189 | — | improper-authorization | security-feature-bypass | — |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB25-26
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →