Executive brief
Adobe Commerce, a popular e-commerce platform used for managing online stores, is affected by a security flaw that allows high-privileged users to inject malicious scripts into the administrative interface. If an administrator views a page containing this malicious script, it could execute in their browser, potentially leading to unauthorized actions or data access within the store management console. This risk is primarily internal, as it requires an attacker to already have significant administrative access.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Commerce due to improper neutralization of input during web page generation (CWE-79). A high-privileged attacker can inject malicious JavaScript into specific form fields within the application. This script is then stored on the server and executed in the context of another user's browser session (typically another administrator) when they navigate to the affected page. The attack requires network access and high-level privileges (PR:H) as well as some user interaction (UI:R). Successful exploitation results in a changed scope (S:C), allowing for limited impact on confidentiality and integrity.
Affected products
- Adobe Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
- Adobe Magento Open Source 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory