HomeSecurityAdobe Commerce bug allows account takeover

Adobe Commerce bug allows account takeover

Adobe has warned of a critical flaw in its Commerce and Magento Open Source, which, if successfully exploited, could allow attackers to take control of customer accounts.

See also: Adobe brings Premiere video editing to iPhone

Adobe

The vulnerability, tracked as CVE-2025-54236 (also known as SessionReaper), has a CVSS score of 9.1 out of a maximum of 10.0. It is described as an improper input validation error. Adobe said it is not aware of any exploits in the wild.

“A potential attacker could compromise customer accounts in Adobe Commerce via the Commerce REST API,” Adobe said in an advisory issued today.

The issue affects the following products and versions:

– 2.4.9-alpha2 and earlier
– 2.4.8-p2 and earlier
– 2.4.7-p7 and earlier
– 2.4.6-p12 and earlier
– 2.4.5-p14 and earlier
– 2.4.4-p15 and earlier
– 1.5.3-alpha2 and earlier
– 1.5.2-p2 and earlier
– 1.4.2-p7 and earlier
– 1.3.4-p14 and earlier
– 1.3.3-p15 and earlier
– Versions 0.1.0 to 0.4.0

See also: Adobe: Releases Firefly apps for iOS and Android

Adobe Commerce bug allows account takeover

Adobe, in addition to releasing a hotfix for the vulnerability, said it has deployed rules for its web application firewall (WAF) to protect environments from exploit attempts that may target merchants using Adobe Commerce on Cloud.

“SessionReaper is one of the most serious Magento vulnerabilities in its history, comparable to Shoplift (2015), Ambionics SQLi (2019), TrojanOrder (2022) and CosmicSting (2024),” e-commerce security firm Sansec.

The company based in the Netherlands reported that it successfully reproduced a possible exploitation method for CVE-2025-54236, but noted that there are also other possible ways to exploit the vulnerability.

“The vulnerability follows a familiar pattern from last year’s CosmicSting attack,” he added. “The attack combines a malicious session with a built-in unsubscription bug in Magento’s REST API.”

“The specific method of remote code execution appears to require file‑based session storage. However, we recommend that merchants using Redis or database sessions take immediate action, as there are many ways to exploit this vulnerability.“

See also: Adobe: Brings Photoshop (beta) to Android users

Adobe Commerce bug allows account takeover

Adobe has also released fixes to mitigate a critical path vulnerability in ColdFusion (CVE-2025-54261, CVSS score: 9.0) that could lead to arbitrary file system writes. It affects ColdFusion 2021 (Update 21 and earlier), 2023 (Update 15 and earlier), and 2025 (Update 3 and earlier) across all platforms.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS