Unvalidated Redirect in Magento Long Term Support Affects E-commerce Operations
CVE-2026-42207

6.1MEDIUM

Key Information:

Vendor

Openmage

Vendor
CVE Published:
15 May 2026

What is CVE-2026-42207?

In Magento Long Term Support (LTS) prior to version 20.18.0, an unvalidated redirect vulnerability exists within the Mage_ProductAlert_AddController::stockAction() method. This occurs when the uenc query parameter is used directly in the redirection process without validation, allowing attackers to specify arbitrary URLs. If a supplied product_id does not correspond to any catalog product, the application may redirect users to potentially malicious sites via HTTP 302 redirects, posing security risks to users and applications dependent on Magento.

Affected Version(s)

magento-lts < 20.18.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.