Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-48000
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-48000 is an Improper Redirect (Open Redirect) vulnerability in Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and Adobe Commerce Events (Adobe I/O Events). It allows unauthenticated remote attackers to craft malicious URLs that redirect victims to attacker-controlled sites, potentially enabling credential theft and account takeover. The vulnerability was disclosed and patched on July 14, 2026. Affected versions include Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier; Adobe Commerce B2B 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier; Magento Open Source 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, and 2.4.6-p15 and earlier; and Adobe Commerce Events (I/O Events) versions 1.6.0 through 1.20.0. The CVSS v3.1 base score is 6.1 (Medium) per Adobe's advisory, though the GitHub Advisory Database scores it as 4.3 (Moderate) (Adobe Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), arising from insufficient validation of user-supplied URL parameters that control redirect destinations within the Adobe Commerce application. An unauthenticated attacker can craft a specially formed URL hosted on or referencing the vulnerable Adobe Commerce instance that, when followed by a victim, causes the application to redirect the user's browser to an arbitrary external site. Exploitation requires no privileges on the platform but does require user interaction — specifically, a victim must click on the malicious link. No technical write-ups or public proof-of-concept code have been identified at this time (Adobe Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from a legitimate Adobe Commerce storefront to an attacker-controlled website, facilitating phishing attacks, credential harvesting, and potential account takeover. The confidentiality and integrity impacts are limited — there is no direct server-side data exposure or code execution — but the social engineering potential is significant for e-commerce environments where users may enter payment or login credentials on spoofed pages. Availability is not impacted by this vulnerability (Adobe Advisory, GitHub Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.35–0.74%, indicating a low near-term exploitation probability. Exploitation is non-automated (requires user interaction via clicking a malicious link) and no threat actor attribution has been reported (GitHub Advisory, Adobe Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Adobe Commerce or Magento Open Source storefronts running affected versions (2.4.9, 2.4.8-p5 and earlier, etc.) using tools like Shodan, Censys, or passive DNS enumeration.
  2. Identify redirect parameter: Locate URL parameters within the Adobe Commerce application that accept redirect destinations (e.g., parameters such as return, redirect, or next in login, checkout, or account pages).
  3. Craft malicious URL: Construct a URL pointing to the legitimate Adobe Commerce store that includes a manipulated redirect parameter pointing to an attacker-controlled domain (e.g., https://legitimate-store.com/customer/account/login/?return=https://attacker.com/phishing).
  4. Deliver to victim: Distribute the crafted URL via phishing email, SMS, social media, or other channels, presenting it as a legitimate store link to increase victim trust.
  5. Harvest credentials: When the victim clicks the link and is redirected to the attacker-controlled site (which may mimic the store's login or payment page), capture submitted credentials or payment information for account takeover (Adobe Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP 302/301 redirect responses from the Adobe Commerce server pointing to external, non-whitelisted domains in server access logs; unusual referrer headers in web server logs showing traffic originating from the Commerce store to external phishing domains.
  • Logs: Web server access logs showing requests to login, checkout, or account endpoints with URL-encoded external domains in redirect parameters (e.g., return=https%3A%2F%2Fattacker.com); repeated requests to redirect-capable endpoints from a single IP or user agent.
  • User Reports: Increased reports from customers of being redirected to unexpected external sites after clicking store links, or phishing pages mimicking the store's login interface.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability. Users should upgrade to the following fixed releases: Adobe Commerce 2.4.9-patched, 2.4.8-p6, 2.4.7-p11, 2.4.6-p16, 2.4.5-p18, or 2.4.4-p19; Adobe Commerce B2B 1.5.3-patched, 1.5.2-p6, 1.4.2-p11, 1.3.4-p18, or 1.3.3-p19; Magento Open Source 2.4.9-patched, 2.4.8-p6, 2.4.7-p11, or 2.4.6-p16; and Adobe Commerce Events (I/O Events) 1.21.0. As interim mitigations, administrators should implement server-side URL validation to restrict redirect destinations to trusted domains, and educate users to verify URLs before clicking links and to be cautious of unexpected redirects (Adobe Advisory).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in July 2026, including CVE-2026-48000, flagging the broader patch batch as potentially allowing arbitrary code execution across various Adobe products. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its moderate severity rating and lack of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77111HIGH8.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77774HIGH8.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77109HIGH8.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77110HIGH7.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77108HIGH7.5
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management