Junglewise Threat Intelligence

CVE-2026-48414: Adobe Commerce stored cross-site scripting in form fields

CVE-2026-48414 · Severity: high · CVSS 7.7 · Published 2026-08-11

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a widely-used e-commerce platform, contains a stored cross-site scripting (XSS) vulnerability in form fields that allows low-privileged attackers to inject malicious scripts. When legitimate users browse pages with the injected content, the attacker's JavaScript executes in their browsers, potentially enabling account takeover, session hijacking, or unauthorized administrative actions. The impact depends on specific deployment conditions and user interactions.

Technical details

The vulnerability is a stored (persistent) cross-site scripting flaw in form field handling within Adobe Commerce. A low-privileged attacker can inject malicious JavaScript into vulnerable form fields; this payload is stored in the application and executed in the browsers of any users who view the affected page. The attack vector is network-based and requires user interaction (a victim must browse the page), but does not require administrative privileges to inject the payload. An attacker can achieve account compromise, session hijacking, or privilege escalation depending on the victim's role. Patch availability status is unclear from the provided information.

Affected products

  • Adobe Commerce

Timeline

  • 2026-08-11: disclosed

References

Related threats