Junglewise Threat Intelligence

CVE-2026-48000: Adobe Commerce open redirect in web interface

CVE-2026-48000 · Severity: medium · CVSS 4.3 · Published 2026-07-14

Technologies: Adobe Magento Enterprise Edition, Adobe Commerce, Adobe Magento Open Source, Adobe Commerce B2b, Adobe Commerce Webhooks Plugin. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used for online storefronts, is affected by a security flaw that allows attackers to redirect users to malicious websites. By tricking a customer or administrator into clicking a specially crafted link, an attacker could send them to a fake login page to steal their credentials or take over their account. This could lead to unauthorized access to customer data or store management functions.

Technical details

An Improper Redirect (Open Redirect) vulnerability exists in Adobe Commerce, Magento Open Source, and related components due to insufficient validation of user-supplied input used in redirection targets (CWE-601). An unauthenticated remote attacker can exploit this by crafting a malicious URL that, when clicked by a victim, redirects the user's browser to an arbitrary external domain. This bypasses security expectations and is typically leveraged in phishing campaigns to facilitate credential theft or session hijacking. The vulnerability requires user interaction (clicking a link) and affects multiple versions including Adobe Commerce 2.4.x and Magento Open Source 2.4.x. Patches have been released in the July 2026 update cycle.

Affected products

  • Adobe Adobe Commerce <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17, 2.4.4-p18
  • Adobe Adobe Commerce B2B <= 1.5.3, 1.5.2-p5, 1.4.2-p10, 1.3.4-p17, 1.3.3-p18
  • Adobe Magento Open Source <= 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15
  • Adobe Adobe Commerce Webhooks Plugin <= 1.20.0

Timeline

  • 2026-07-14: advisory: Initial advisory published by Adobe (APSB26-73) and NVD.

References

Related threats