Executive brief
Adobe Commerce, a popular e-commerce platform used for online storefronts, is affected by a security flaw that allows attackers to redirect users to malicious websites. By tricking a customer or administrator into clicking a specially crafted link, an attacker could send them to a fake login page to steal their credentials or take over their account. This could lead to unauthorized access to customer data or store management functions.
Technical details
An Improper Redirect (Open Redirect) vulnerability exists in Adobe Commerce, Magento Open Source, and related components due to insufficient validation of user-supplied input used in redirection targets (CWE-601). An unauthenticated remote attacker can exploit this by crafting a malicious URL that, when clicked by a victim, redirects the user's browser to an arbitrary external domain. This bypasses security expectations and is typically leveraged in phishing campaigns to facilitate credential theft or session hijacking. The vulnerability requires user interaction (clicking a link) and affects multiple versions including Adobe Commerce 2.4.x and Magento Open Source 2.4.x. Patches have been released in the July 2026 update cycle.
Affected products
- Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
- Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
- Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
- Adobe Adobe Commerce Webhooks Plugin <= 1.20.0
Timeline
- 2026-07-14: advisory: Initial advisory published by Adobe (APSB26-73) and NVD.