PT-2026-6440 · Packagist · Openmage Magento Lts

Published

2026-02-02

·

Updated

2026-02-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Impact

The admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations.

Patches

The bug comes from the Zend library and is patche by unsetting the header in the bootstrap process.

Workarounds

Unset the X-Original-Url header in the web server configuration.

References

The activation of these headers is coming from the Zend Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..)

Credit

Anees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x dev/hacktivity

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

GHSA-JG68-VHV3-9R8F

Affected Products

Openmage Magento Lts