
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21295 is a URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Adobe Commerce and Magento Open Source. It affects Adobe Commerce versions 2.4.4 through 2.4.4-p16, 2.4.5 through 2.4.5-p15, 2.4.6 through 2.4.6-p13, 2.4.7 through 2.4.7-p8, 2.4.8 through 2.4.8-p3, and 2.4.9-alpha3 and earlier; Magento Open Source versions 2.4.5 through 2.4.5-p15, 2.4.6 through 2.4.6-p13, 2.4.7 through 2.4.7-p8, and 2.4.8 through 2.4.8-p3; and Adobe Commerce B2B versions 1.3.3 through 1.5.2-p3. Disclosed on March 10, 2026, and published to NVD on March 11, 2026, it carries a CVSS v3.1 base score of 3.1 (Low) (Adobe Advisory).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'). An unauthenticated, network-based attacker can craft a malicious URL that, when followed by a victim user, causes the Adobe Commerce or Magento application to redirect the user to an attacker-controlled external site. Exploitation requires user interaction — specifically, a victim must click or follow the crafted link — and the attack complexity is rated High, limiting opportunistic exploitation (Adobe Advisory).
Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from a trusted Adobe Commerce or Magento storefront to a malicious external website, facilitating phishing attacks, credential harvesting, or malware delivery. The vulnerability has no direct impact on confidentiality or availability of the affected system itself, and integrity impact is rated Low. The primary risk is social engineering against end users or administrators who trust the originating domain (Adobe Advisory).
returnUrl, redirect, or similar parameter in login, checkout, or OAuth flows).https://victim-store.com/customer/account/login/?returnUrl=https://attacker.com/phishing).returnUrl, redirect, next, or similar parameters containing external URLs; repeated access from the same IP to redirect-capable endpoints with varying destination URLs.Adobe has released patched versions addressing this vulnerability. Users should upgrade to the following or later versions: Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3; Magento Open Source 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3; and Adobe Commerce B2B 1.3.3-p16, 1.3.4-p15, 1.3.5-p13, 1.4.2-p8, 1.5.2-p3. No specific configuration-based workaround has been published; upgrading to a patched release is the recommended remediation. Additionally, implementing network-level controls to restrict access to admin interfaces and educating users about phishing risks can reduce exposure (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products addressed in the March 2026 patch cycle, including this CVE, flagging the broader release as potentially allowing arbitrary code execution across the product suite (CIS Advisory). Community coverage was limited given the Low CVSS score, with automated CVE tracking feeds and threat intelligence platforms (e.g., BeyondMachines, VulDB, Offseq Radar) picking up the disclosure shortly after Adobe's March 10, 2026 bulletin. No significant researcher commentary or media coverage specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."