CVE-2026-25523Patch(openmage / magento)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openmage magento systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magento

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
magento

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-04: 1Mentions · 2026-02-12: 2Mentions · 2026-10-07: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 102-0402-1210-07
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-02-122
Disclosure1General1
Full discourse4 posts
  • Anees Hyder@aneesOx_dev
    Disclosure

    Just got my first CVE from a HackerOne report - CVE-2026-25523 Grateful to be contributing to real-world security in open-source software. More coming. 💻🔐 #cve #hackerone #cybersecurity #BugBounty

    Post summary

    A user announces that they have received a new CVE (CVE-2026-25523) from a HackerOne report and plans to report more in the future.

    20030111
    99 followersView on X
  • Anees Hyder@aneesOx_dev

    @itspraveen70140 @ni5arga I once got a CVE from a website issue, it depends on the issue. https://www.cve.org/CVERecord?id=CVE-2026-25523

    0002061
    99 followersView on X
  • Anees Hyder@aneesOx_dev
    General

    https://nvd.nist.gov/vuln/detail/CVE-2026-25523 https://github.com/advisories/GHSA-jg68-vhv3-9r8f

    Post summary

    The text consists solely of two URLs pointing to CVE references, with no additional context or actionable information provided.

    0002066
    99 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25523 Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of… https://www.cve.org/CVERecord?id=CVE-2026-25523

    Post summary

    CVE-2026-25523 allows discovery of the Magento admin URL in versions before 20.16.1; the issue is fixed in v20.16.1.

    00010188
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenmagemagento---

Explore more