CVE-2026-48000: Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48000?
The severity of CVE-2026-48000 is rated medium with a score of 6.1.
How do I fix CVE-2026-48000?
To fix CVE-2026-48000, update Adobe Commerce to the latest version that addresses this vulnerability.
What types of attacks are possible due to CVE-2026-48000?
CVE-2026-48000 allows attacks such as open redirect, which can lead to credential theft and account takeover.
Which software versions are affected by CVE-2026-48000?
CVE-2026-48000 affects Adobe Commerce, Adobe Commerce B2B, and Adobe Magento.
What impacts does CVE-2026-48000 have on users?
Users of Adobe Commerce may be exposed to untrusted redirection potentially leading to phishing or malicious sites.