VYPR
Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026

Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)

CVE-2026-48000

Description

Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a victim must click on a malicious link.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.