Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability in Adobe Commerce allows an unauthorized person to take over user accounts. Attackers can exploit this issue remotely, without any interaction from the user, to gain unauthorized access to sensitive information and make changes to data.
- E-commerce platforms are a target.
- User accounts and data are at risk.
- No user interaction needed for attack.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by sending crafted requests to the Commerce REST API. This allows them to hijack active user sessions, gaining unauthorized access to user accounts and sensitive data. The attacker would specifically target the API endpoints responsible for session management to achieve this session takeover.
- No user interaction needed.
- Target the Commerce REST API.
- Session management flaws exploited.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability is highly likely to be weaponized. Attackers target e-commerce platforms because they offer direct access to sensitive customer data and financial information, making session takeover a valuable attack vector for immediate monetization or further compromise. The lack of user interaction and network exploitability further increase its attractiveness.
- Exploited via public exploit.
- Listed on CISA's KEV.
- Recent KEV listing.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
Prioritize patching Adobe Commerce versions 2.4.4 through 2.4.9-alpha2. This critical vulnerability allows unauthenticated session takeover, directly impacting confidentiality and integrity. Given its inclusion on the Known Exploited Vulnerabilities catalog and high EPSS score, immediate action is required to prevent compromise.
- Apply available patches or upgrade.
- Restrict network access to the Commerce REST API.
- Monitor for unauthorized session activity.