Description
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a victim must click on a malicious link.
Published: 2026-07-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce, including B2B, Webhooks Plugin, and Magento Open Source, has an Improper Redirect (Open Redirect) flaw that allows an attacker to craft a malicious URL. When a user follows the link, they are redirected to an attacker‑controlled site, which can be used for phishing and credential theft. The weakness falls under CWE‑601 and represents an open redirect that bypasses security controls.

Affected Systems

The affected products are Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. No specific version information is listed, so administrators must verify whether their current installations expose this vulnerability and apply remediation accordingly.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating low to moderate severity, and an EPSS score of less than 1%, signifying a low probability of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires user interaction—typically clicking a crafted link—making it a social engineering vector rather than an automated attack. Attackers can leverage the redirect to conduct phishing, credential theft, or account takeover, but the system itself remains otherwise unaffected.

Generated by OpenCVE AI on July 31, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, or Magento Open Source patch that fixes the open redirect flaw
  • Configure the application to allow redirects only to approved domains, or implement a web application firewall rule that blocks redirects to external sites
  • Educate users about phishing and encourage them to verify URLs before clicking, supplementing with link protection tools

Generated by OpenCVE AI on July 31, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe adobe Commerce Webhooks Plugin
Adobe magento Open Source

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a victim must click on a malicious link.
Title Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Adobe Commerce Webhooks Plugin Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-07-16T14:46:10.054Z

Reserved: 2026-05-20T15:50:31.368Z

Link: CVE-2026-48000

cve-icon Vulnrichment

Updated: 2026-07-16T14:46:06.344Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:53:10Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')