CVE-2026-25523
Unknown Unknown - Not Provided

Information Disclosure via X-Original-Url in Magento-lts Admin URL

Vulnerability report for CVE-2026-25523, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-04

Last updated on: 2026-02-20

Assigner: GitHub, Inc.

Description

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-04
Last Modified
2026-02-20
Generated
2026-07-26
AI Q&A
2026-02-05
EPSS Evaluated
2026-07-25
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openmage magento to 20.16.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Magento-lts versions prior to 20.16.1. It allows an attacker to discover the admin URL without prior knowledge by exploiting the X-Original-Url header on certain configurations. This means that the location of the admin interface, which is typically hidden for security reasons, can be revealed through this flaw.

Detection Guidance

I don't know

Impact Analysis

The impact of this vulnerability is that an attacker can identify the admin URL of a Magento-lts installation without authorization. This could potentially lead to targeted attacks against the admin interface, increasing the risk of unauthorized access or further exploitation.

Compliance Impact

I don't know

Mitigation Strategies

To mitigate this vulnerability, upgrade Magento-lts to version 20.16.1 or later, where the issue with the admin URL disclosure via the X-Original-Url header has been patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25523. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart