Junglewise Threat Intelligence

CVE-2026-21291: Adobe Commerce stored cross-site scripting in form fields

CVE-2026-21291 · Severity: medium · CVSS 4.8 · Published 2026-03-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is a widely-used e-commerce platform that powers online stores. A stored cross-site scripting (XSS) vulnerability allows a highly-privileged attacker to inject malicious scripts into form fields, which then execute when customers or staff browse to affected pages. This could be used to steal customer data, compromise admin accounts, or redirect users to malicious sites.

Technical details

A stored XSS vulnerability exists in Adobe Commerce form field handling that permits high-privileged attackers to inject persistent malicious JavaScript. The vulnerable component stores unsanitized user input in form fields, which is later rendered without proper encoding when pages are viewed. Exploitation requires both high-level administrative access to inject the payload and user interaction (victim must visit the page containing the malicious field). Once injected, the script executes in the browser context of anyone accessing the affected form, potentially compromising session tokens or sensitive data. Patches are available for affected versions.

Affected products

  • Adobe Commerce 2.4.4-p16 and earlier

Timeline

  • 2026-03-11: disclosed

References

Related threats