Junglewise Threat Intelligence

CVE-2026-21295: Adobe Commerce open redirect vulnerability

CVE-2026-21295 · Severity: low · CVSS 3.1 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an e-commerce platform used by online retailers to manage product catalogs, shopping carts, and customer transactions. This vulnerability allows an attacker to craft malicious links that redirect customers to fraudulent websites while appearing to come from the legitimate store, potentially leading to credential theft or financial fraud. Exploitation requires a customer to click a malicious link.

Technical details

This is an Open Redirect (CWE-601) vulnerability in Adobe Commerce that allows attackers to craft URLs pointing to malicious external sites. The vulnerable component fails to properly validate redirect destinations before redirecting users. The attack vector is network-based and requires user interaction—an attacker must trick a customer into clicking a crafted link. An attacker can redirect users to phishing sites or malware distribution points while maintaining the appearance of a legitimate storefront. Adobe has issued patches for affected versions 2.4.4-p16 and later.

Affected products

  • Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier

Timeline

  • 2026-03-11: disclosed

References

Related threats