Unvalidated Redirect in Magento Long Term Support Affects E-commerce Operations
CVE-2026-42207
6.1MEDIUM
What is CVE-2026-42207?
In Magento Long Term Support (LTS) prior to version 20.18.0, an unvalidated redirect vulnerability exists within the Mage_ProductAlert_AddController::stockAction() method. This occurs when the uenc query parameter is used directly in the redirection process without validation, allowing attackers to specify arbitrary URLs. If a supplied product_id does not correspond to any catalog product, the application may redirect users to potentially malicious sites via HTTP 302 redirects, posing security risks to users and applications dependent on Magento.
Affected Version(s)
magento-lts < 20.18.0
