OpenMage Magento-LTS Admin URL Discovery Vulnerability via X-Original-Url Header

Vulnerability

A vulnerability in OpenMage Magento-LTS prior to version 20.16.1 allows the admin URL to be discovered without prior knowledge of its location. This is achieved by exploiting the X-Original-Url header on certain configurations, potentially leading to unauthorized access to the admin interface.

Impact

Exploitation of this vulnerability could result in unauthorized discovery of the admin URL, allowing for potential unauthorized access to the admin interface.

Remediation

Users can update to OpenMage Magento-LTS versions 20.16.1 or 20.17.0, where this vulnerability has been patched. Alternatively, the X-Original-Url header can be unset in the web server configuration.

Added: Feb 4, 2026, 10:30 PM
Updated: Feb 4, 2026, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.