CVE-2025-22386
CVE-2025-22386 is a high-severity vulnerability in Optimizely Configured Commerce with a CVSS 3.x base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-613.
Key facts
- Severity: High (CVSS 3.x base score 7.3)
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-2767
- Weakness: CWE-613
- Affected product: Optimizely Configured Commerce
- Published:
- Last modified:
Description
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.
Frequently asked questions
- What is CVE-2025-22386?
- An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.
- How severe is CVE-2025-22386?
- CVE-2025-22386 has a CVSS 3.x base score of 7.3, rated high severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2025-22386 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-22386?
- CVE-2025-22386 affects Optimizely Configured Commerce. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-22386?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2025-22386 have an EU (EUVD) identifier?
- Yes. CVE-2025-22386 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-2767.
- When was CVE-2025-22386 published?
- CVE-2025-22386 was published on 2025-01-04 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:optimizely:configured_commerce:*:*:*:*:*:*:*:*
More vulnerabilities in Optimizely Configured Commerce
- CVE-2024-56174 — High (CVSS 8.1): In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users'…
- CVE-2025-22387 — High (CVSS 7.5): An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests…
- CVE-2025-22384 — High (CVSS 7.5): An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business…
- CVE-2024-56175 — Medium (CVSS 6.1): In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users'…
- CVE-2025-22385 — Medium (CVSS 5.9): An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B…
- CVE-2024-56173 — Medium (CVSS 4.7): In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users'…
All CVEs affecting Optimizely Configured Commerce →
Other CWE-613 (Insufficient Session Expiration) vulnerabilities
- CVE-2024-8888 — Critical (CVSS 10.0): An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the…
- CVE-2026-79313 — Critical (CVSS 9.8): webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on…
- CVE-2026-82311 — Critical (CVSS 9.8): Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions,…
- CVE-2026-84480 — Critical (CVSS 9.8): WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to…
- CVE-2026-14950 — Critical (CVSS 9.8): An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session…
- CVE-2026-46455 — Critical (CVSS 9.8): Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper…
Browse all CWE-613 (Insufficient Session Expiration) vulnerabilities →