CVE-2026-25523: Openmage Magento
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.
Affected products
- Openmage Magento: up to and including 20.16.0
Published 2026-02-04. Last modified 2026-06-17.