CVE-2026-25523
EUVD-2026-533004.02.2026, 22:15
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openmage | magento | 𝑥 ≤ 20.16.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration