CVE-2026-21295
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-21295 is a URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Adobe Commerce and Magento Open Source. It affects Adobe Commerce versions 2.4.4 through 2.4.4-p16, 2.4.5 through 2.4.5-p15, 2.4.6 through 2.4.6-p13, 2.4.7 through 2.4.7-p8, 2.4.8 through 2.4.8-p3, and 2.4.9-alpha3 and earlier; Magento Open Source versions 2.4.5 through 2.4.5-p15, 2.4.6 through 2.4.6-p13, 2.4.7 through 2.4.7-p8, and 2.4.8 through 2.4.8-p3; and Adobe Commerce B2B versions 1.3.3 through 1.5.2-p3. Disclosed on March 10, 2026, and published to NVD on March 11, 2026, it carries a CVSS v3.1 base score of 3.1 (Low) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'). An unauthenticated, network-based attacker can craft a malicious URL that, when followed by a victim user, causes the Adobe Commerce or Magento application to redirect the user to an attacker-controlled external site. Exploitation requires user interaction — specifically, a victim must click or follow the crafted link — and the attack complexity is rated High, limiting opportunistic exploitation (Adobe Advisory).

Impact

Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from a trusted Adobe Commerce or Magento storefront to a malicious external website, facilitating phishing attacks, credential harvesting, or malware delivery. The vulnerability has no direct impact on confidentiality or availability of the affected system itself, and integrity impact is rated Low. The primary risk is social engineering against end users or administrators who trust the originating domain (Adobe Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Adobe Commerce or Magento storefronts running affected versions (prior to the March 2026 patches) using tools like Shodan, Censys, or manual version fingerprinting via HTTP response headers or known URL patterns.
  2. Identify redirect parameter: Locate a URL parameter or endpoint within the application that performs client-side or server-side redirects without adequate validation (e.g., a returnUrl, redirect, or similar parameter in login, checkout, or OAuth flows).
  3. Craft malicious URL: Construct a URL pointing to the legitimate Adobe Commerce/Magento domain but embedding a redirect to an attacker-controlled site (e.g., https://victim-store.com/customer/account/login/?returnUrl=https://attacker.com/phishing).
  4. Deliver to target: Send the crafted URL to a victim via phishing email, social media, or other communication channels, leveraging the trusted domain to increase click-through likelihood.
  5. Harvest credentials or deliver malware: When the victim clicks the link and interacts with the legitimate site, they are transparently redirected to the attacker's site, where credentials can be harvested or malicious content served (Adobe Advisory).

Indicators of compromise

  • Network: Outbound HTTP 302/301 redirect responses from the Commerce/Magento server pointing to external, non-whitelisted domains; unusual referrer headers in web server logs originating from the Magento domain to external sites.
  • Logs: Web server access logs showing requests to login, checkout, or OAuth endpoints with suspicious returnUrl, redirect, next, or similar parameters containing external URLs; repeated access from the same IP to redirect-capable endpoints with varying destination URLs.
  • Application: Presence of external domain values in redirect-related URL parameters in application request logs that do not match the store's configured base URL or allowed redirect domains.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability. Users should upgrade to the following or later versions: Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3; Magento Open Source 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3; and Adobe Commerce B2B 1.3.3-p16, 1.3.4-p15, 1.3.5-p13, 1.4.2-p8, 1.5.2-p3. No specific configuration-based workaround has been published; upgrading to a patched release is the recommended remediation. Additionally, implementing network-level controls to restrict access to admin interfaces and educating users about phishing risks can reduce exposure (Adobe Advisory).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products addressed in the March 2026 patch cycle, including this CVE, flagging the broader release as potentially allowing arbitrary code execution across the product suite (CIS Advisory). Community coverage was limited given the Low CVSS score, with automated CVE tracking feeds and threat intelligence platforms (e.g., BeyondMachines, VulDB, Offseq Radar) picking up the disclosure shortly after Adobe's March 10, 2026 bulletin. No significant researcher commentary or media coverage specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48358CRITICAL10
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48356CRITICAL9.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48000MEDIUM6.1
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48371MEDIUM5.4
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48001LOW3.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management