Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. | Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 03 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe adobe Commerce Adobe adobe Commerce B2b Adobe adobe Commerce Webhooks Plugin Adobe magento Open Source |
|
| Vendors & Products |
Adobe
Adobe adobe Commerce Adobe adobe Commerce B2b Adobe adobe Commerce Webhooks Plugin Adobe magento Open Source |
Thu, 16 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Jul 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site, potentially enabling credential theft and account takeover. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. | |
| Title | Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601) | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2026-08-06T16:02:00.254Z
Reserved: 2026-05-20T15:50:31.368Z
Link: CVE-2026-48000
Updated: 2026-07-16T14:46:06.344Z
Status : Analyzed
Published: 2026-07-14T20:17:05.320
Modified: 2026-08-07T15:42:49.667
Link: CVE-2026-48000
No data.
OpenCVE Enrichment
Updated: 2026-08-07T01:45:05Z