Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
CVE-2026-48000
Description
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a victim must click on a malicious link.
Affected products
1Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/magento/apsb26-73.htmlmitrevendor-advisory
News mentions
0No linked articles in our index yet.