A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-54263

CVE-2025-54263: Adobe Commerce Auth Bypass Vulnerability

CVE-2025-54263 is an incorrect authorization vulnerability in Adobe Commerce that allows low-privileged attackers to bypass security measures and maintain unauthorized access. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published: May 26, 2026

CVE-2025-54263 Overview

CVE-2025-54263 is an Incorrect Authorization vulnerability [CWE-863] affecting Adobe Commerce, Adobe Commerce B2B, and Adobe Magento Open Source. A low-privileged authenticated attacker can leverage the flaw to bypass security controls and maintain unauthorized access to affected installations. Exploitation requires network access but no user interaction, making it suitable for automated attacks against exposed storefronts.

Adobe published the issue in security bulletin APSB25-94, covering multiple branches of the Commerce platform. The vulnerability impacts confidentiality and integrity of merchant data, customer records, and administrative resources.

Critical Impact

A low-privileged attacker with network access can bypass authorization checks in Adobe Commerce to access restricted resources and persist unauthorized access without user interaction.

Affected Products

  • Adobe Commerce 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier
  • Adobe Commerce B2B 1.5.3-alpha2, 1.5.2-p2, 1.4.2-p7, 1.3.5-p12, 1.3.4-p14, 1.3.3-p15 and earlier
  • Adobe Magento Open Source (matching 2.4.x branches)

Discovery Timeline

  • 2025-10-14 - CVE-2025-54263 published to the National Vulnerability Database (NVD)
  • 2025-10-20 - Last updated in NVD database

Technical Details for CVE-2025-54263

Vulnerability Analysis

The flaw resides in Adobe Commerce authorization logic, where access decisions do not adequately validate that an authenticated principal is entitled to the requested resource or action. Because the failure occurs after authentication, any account with low privileges, such as a registered customer or limited backend user, can reach functionality that should be restricted to higher-privileged roles.

The weakness maps to CWE-863: Incorrect Authorization. The CVSS vector indicates a network-reachable issue with low attack complexity and no user interaction, scoped to confidentiality and integrity rather than availability. Successful exploitation enables attackers to maintain unauthorized access across sessions, which can support data theft, tampering with catalog or order data, and lateral movement into administrative workflows.

Root Cause

The root cause is an authorization check that evaluates whether a request is authenticated without enforcing whether the authenticated identity is authorized for the specific object or operation. This pattern often arises when role checks are applied at controller entry points but not at the data access layer, allowing crafted requests to reach protected functionality through alternate paths.

Attack Vector

An attacker creates or compromises a low-privileged account on the storefront. Using that session, the attacker issues HTTP requests against endpoints whose authorization logic is incomplete, retrieving or modifying resources owned by other tenants, customers, or administrators. No social engineering or victim interaction is needed, and the attack can be repeated to retain access. Adobe has not published exploitation details, and no public proof-of-concept code is currently available.

Detection Methods for CVE-2025-54263

Indicators of Compromise

  • Unexpected access to admin or B2B endpoints from accounts that historically only used customer-facing routes.
  • Creation of new administrative users, API integrations, or OAuth tokens shortly after low-privileged logins.
  • Anomalous read or write operations against /rest/V1/, /graphql, or admin controllers from a single session ID.
  • Modifications to order, customer, or catalog records without corresponding admin UI activity.

Detection Strategies

  • Compare authenticated session role claims against the resources accessed per request and alert on mismatches.
  • Hunt for HTTP 200 responses to privileged endpoints from accounts whose role should produce 401 or 403.
  • Baseline normal GraphQL and REST query patterns per customer group and flag deviations.
  • Review web server and application logs for repeated requests that enumerate object IDs across tenants.

Monitoring Recommendations

  • Forward Adobe Commerce application, web server, and database audit logs to a centralized analytics platform for correlation.
  • Monitor for privilege changes, new admin role assignments, and modifications to ACL rules.
  • Track outbound data volume from the Commerce application tier to detect bulk extraction.

How to Mitigate CVE-2025-54263

Immediate Actions Required

  • Apply the patched Adobe Commerce release that corresponds to your deployed branch as listed in security bulletin APSB25-94.
  • Inventory all Commerce, Commerce B2B, and Magento Open Source instances, including non-production environments, and confirm version levels.
  • Audit existing low-privileged accounts, disable dormant users, and rotate API keys and integration tokens.
  • Review recent admin and B2B activity logs for signs of unauthorized access during the exposure window.

Patch Information

Adobe addressed CVE-2025-54263 in the security update documented in the Adobe Magento Security Advisory APSB25-94. Upgrade to the fixed releases for each supported branch, including the latest patches above 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, and 2.4.4-p15, as well as the corresponding B2B versions.

Workarounds

  • Restrict access to admin and B2B endpoints with IP allowlisting or VPN-only access until patches are deployed.
  • Place a web application firewall in front of the storefront to inspect and rate-limit authenticated requests to sensitive APIs.
  • Tighten customer group and role permissions to the minimum required for business operations.
bash
# Verify Adobe Commerce version and apply the vendor patch
php bin/magento --version
composer require magento/product-community-edition=2.4.8-p3 --no-update
composer update
php bin/magento setup:upgrade
php bin/magento setup:di:compile
php bin/magento cache:flush

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechAdobe Commerce

  • SeverityHIGH

  • CVSS Score8.1

  • EPSS Probability0.09%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-863
  • Vendor Resources
  • Adobe Magento Security Advisory
  • Related CVEs
  • CVE-2026-34656: Adobe Commerce Auth Bypass Vulnerability

  • CVE-2026-34645: Adobe Commerce Auth Bypass Vulnerability

  • CVE-2026-34685: Adobe Commerce Auth Bypass Vulnerability

  • CVE-2026-34646: Adobe Commerce Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English