
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48000 is an Improper Redirect (Open Redirect) vulnerability in Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and Adobe Commerce Events (Adobe I/O Events). It allows unauthenticated remote attackers to craft malicious URLs that redirect victims to attacker-controlled sites, potentially enabling credential theft and account takeover. The vulnerability was disclosed and patched on July 14, 2026. Affected versions include Adobe Commerce 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, 2.4.6-p15 and earlier, 2.4.5-p17 and earlier, and 2.4.4-p18 and earlier; Adobe Commerce B2B 1.5.3, 1.5.2-p5 and earlier, 1.4.2-p10 and earlier, 1.3.4-p17 and earlier, and 1.3.3-p18 and earlier; Magento Open Source 2.4.9, 2.4.8-p5 and earlier, 2.4.7-p10 and earlier, and 2.4.6-p15 and earlier; and Adobe Commerce Events (I/O Events) versions 1.6.0 through 1.20.0. The CVSS v3.1 base score is 6.1 (Medium) per Adobe's advisory, though the GitHub Advisory Database scores it as 4.3 (Moderate) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), arising from insufficient validation of user-supplied URL parameters that control redirect destinations within the Adobe Commerce application. An unauthenticated attacker can craft a specially formed URL hosted on or referencing the vulnerable Adobe Commerce instance that, when followed by a victim, causes the application to redirect the user's browser to an arbitrary external site. Exploitation requires no privileges on the platform but does require user interaction — specifically, a victim must click on the malicious link. No technical write-ups or public proof-of-concept code have been identified at this time (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from a legitimate Adobe Commerce storefront to an attacker-controlled website, facilitating phishing attacks, credential harvesting, and potential account takeover. The confidentiality and integrity impacts are limited — there is no direct server-side data exposure or code execution — but the social engineering potential is significant for e-commerce environments where users may enter payment or login credentials on spoofed pages. Availability is not impacted by this vulnerability (Adobe Advisory, GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.35–0.74%, indicating a low near-term exploitation probability. Exploitation is non-automated (requires user interaction via clicking a malicious link) and no threat actor attribution has been reported (GitHub Advisory, Adobe Advisory).
return, redirect, or next in login, checkout, or account pages).https://legitimate-store.com/customer/account/login/?return=https://attacker.com/phishing).return=https%3A%2F%2Fattacker.com); repeated requests to redirect-capable endpoints from a single IP or user agent.Adobe has released patched versions addressing this vulnerability. Users should upgrade to the following fixed releases: Adobe Commerce 2.4.9-patched, 2.4.8-p6, 2.4.7-p11, 2.4.6-p16, 2.4.5-p18, or 2.4.4-p19; Adobe Commerce B2B 1.5.3-patched, 1.5.2-p6, 1.4.2-p11, 1.3.4-p18, or 1.3.3-p19; Magento Open Source 2.4.9-patched, 2.4.8-p6, 2.4.7-p11, or 2.4.6-p16; and Adobe Commerce Events (I/O Events) 1.21.0. As interim mitigations, administrators should implement server-side URL validation to restrict redirect destinations to trusted domains, and educate users to verify URLs before clicking links and to be cautious of unexpected redirects (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in July 2026, including CVE-2026-48000, flagging the broader patch batch as potentially allowing arbitrary code execution across various Adobe products. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its moderate severity rating and lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."