
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-48000 is an Improper Redirect (Open Redirect) vulnerability in Adobe Commerce, Adobe Commerce B2B, Magento Open Source, and Adobe Commerce Events (I/O Events plugin). It allows unauthenticated remote attackers to construct malicious URLs that redirect victims to attacker-controlled sites, potentially enabling credential theft and account takeover. The vulnerability was disclosed and patched on July 14, 2026. Affected versions include Adobe Commerce up to 2.4.9/2.4.8-p5/2.4.7-p10/2.4.6-p15/2.4.5-p17/2.4.4-p18, Adobe Commerce B2B up to 1.5.3/1.5.2-p5/1.4.2-p10/1.3.4-p17/1.3.3-p18, Magento Open Source up to 2.4.9/2.4.8-p5/2.4.7-p10/2.4.6-p15, and Adobe Commerce Events (I/O Events) versions 1.6.0 through 1.20.0. The CVSS v3.1 base score is 6.1 (Medium) per the Adobe advisory, while the GitHub Advisory Database rates it 4.3 (Moderate) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'), where the application accepts user-controlled input specifying an external link and uses it in a redirect without adequate validation. An unauthenticated attacker can craft a specially formed URL hosted on or referencing the vulnerable Adobe Commerce or Magento instance that, when followed by a victim, transparently redirects them to an attacker-controlled external site. Exploitation requires no privileges and no special configuration, but does require user interaction — specifically, a victim must click the malicious link. No public proof-of-concept code has been identified (Adobe Advisory, GitHub Advisory).
Successful exploitation enables a security feature bypass, allowing attackers to redirect authenticated or unauthenticated users from a trusted Adobe Commerce or Magento storefront to an attacker-controlled website. The primary risks are credential theft (e.g., via phishing pages mimicking the legitimate store login) and account takeover, which could expose customer payment data, order history, and personal information. Availability and direct confidentiality of server-side data are not impacted by this vulnerability alone, but downstream account compromise could lead to broader data exposure (Adobe Advisory, GitHub Advisory).
returnUrl, redirect, or similar parameter in login, checkout, or account flows).https://legitimate-store.com/customer/account/login/?returnUrl=https://attacker.com/phishing)./customer/account/login/, /checkout/) with returnUrl, redirect, or similar parameters containing external URLs (e.g., http://, https:// pointing to non-store domains).Adobe has released patched versions addressing this vulnerability. Users should upgrade to the following or later versions: Adobe Commerce 2.4.9-patched, 2.4.8-p6, 2.4.7-p11, 2.4.6-p16, 2.4.5-p18, or 2.4.4-p19; Adobe Commerce B2B 1.5.3-patched, 1.5.2-p6, 1.4.2-p11, 1.3.4-p18, or 1.3.3-p19; Magento Open Source 2.4.9-patched, 2.4.8-p6, 2.4.7-p11, or 2.4.6-p16; and Adobe Commerce Events (I/O Events) 1.21.0. As a complementary measure, implement server-side URL validation to restrict redirect destinations to trusted domains, and educate users to verify URLs before clicking links from emails or external sources (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in July 2026, including this open redirect issue. Coverage has been limited to automated vulnerability tracking platforms and aggregators, with no notable independent researcher commentary or significant social media discussion identified at this time (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."