Published Aug 12, 2025.
Improper access control (CVE-2025-49557) and related flaws that let an attacker bypass security features and reach functionality that should require authorization. Shipped with the regular August 2025 patch set for the 2.4.4 to 2.4.8 lines.
| CVE | CVSS | Type | Impact | Auth required |
|---|---|---|---|---|
| CVE-2025-49557 | — | improper-access-control | security-feature-bypass | no |
Get this bulletin as JSON:
curl -s https://magento.watch/api/v1/security-bulletins/APSB25-71
magento.watch is built and maintained by Łukasz Bajsarowicz, solo, on weekends. If it has saved you a few hours, consider chipping in.
Sponsor →Łukasz takes on Magento 2 and Adobe Commerce engagements — upgrades, audits, performance, team mentoring.
Get in touch →