Executive brief
Adobe Commerce and Magento, popular e-commerce platforms used for online storefronts, are affected by a security flaw that allows attackers to inject malicious scripts into website forms. An attacker with low-level account access could use this to target other users, including administrators, potentially leading to account takeover or unauthorized access to sensitive customer and business data. This could result in significant operational disruption and reputational damage if customer sessions are compromised.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Adobe Commerce and Magento Open Source due to improper neutralization of input during web page generation (CWE-79). A low-privileged attacker can inject malicious JavaScript into vulnerable form fields. This script is then executed in the context of a victim's browser when they navigate to the affected page. Because the vulnerability has a 'Changed' scope (S:C), it can be used to transition from the user's browser session to accessing sensitive administrative functions or session tokens. The vulnerability is reachable over the network and requires low-privileged authentication and minimal user interaction (viewing the page). Patching information is available via Adobe advisory APSB26-49.
Affected products
- Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
- Adobe Magento Open Source 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by Adobe and NVD