Open redirect in Adobe products - CVE-2026-21295
Published: March 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
Affected software
Magento Open Source
Adobe Commerce (formerly Magento Commerce)
How to mitigate CVE-2026-21295
Magento Open Source - addressed in versions 2.4.5‑p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, 2.4.9‑beta1
Adobe Commerce (formerly Magento Commerce) - addressed in versions 2.4.4‑p17, 2.4.5‑p16, 2.4.6‑p14, 2.4.7‑p9, 2.4.8‑p4, 2.4.9‑beta1