CRITICAL

APSB25-26: Security update available for Adobe Commerce

Published Apr 8, 2025.

Improper authorization (CVE-2025-27189) allowing a security feature bypass, published alongside the 2.4.8 general availability release. Older lines receive the fix through their April 2025 patch versions.

Published
Apr 8, 2025
Severity
critical
CVEs
1
Isolated patch
no

CVEs

CVEs in APSB25-26
CVE CVSS Type Impact Auth required
CVE-2025-27189 improper-authorization security-feature-bypass

Fixed in

Magento Open Source
2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13
Adobe Commerce
2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13
Mage-OS

References

For integrators

Get this bulletin as JSON:

curl -s https://magento.watch/api/v1/security-bulletins/APSB25-26