Junglewise Threat Intelligence

CVE-2026-21290: Adobe Commerce stored cross-site scripting in form fields

CVE-2026-21290 · Severity: high · CVSS 8.7 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform, contains a stored cross-site scripting (XSS) vulnerability in form fields that allows attackers with limited privileges to inject malicious scripts. When an administrator or authorized user views a page containing the compromised field, the attacker's script runs in their browser, enabling session hijacking and potential account takeover with access to sensitive business and customer data.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Adobe Commerce form fields that permits a low-privileged attacker to persist malicious JavaScript payloads. The attack requires user interaction—a victim must navigate to a page containing the vulnerable field for the script to execute in their browser context. Successful exploitation allows an attacker to perform actions as the victim, including session hijacking and manipulation of sensitive data. The vulnerability affects versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier. Patches are available through Adobe's security advisories.

Affected products

  • Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier

Timeline

  • 2026-03-11: disclosed

References

Related threats