Junglewise Threat Intelligence

CVE-2026-76201: Adobe Commerce stored XSS in form fields

CVE-2026-76201 · Severity: critical · CVSS 9.3 · Published 2026-09-08

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce is an e-commerce platform used by retailers to manage online stores and customer transactions. A stored cross-site scripting vulnerability allows attackers to inject malicious scripts into form fields, which execute when administrators or customers view affected pages. Successful exploitation could lead to account takeover, session hijacking, or theft of sensitive customer or business data.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Adobe Commerce that permits injection of malicious JavaScript into form fields without proper sanitization or encoding. The vulnerability changes scope, meaning an attacker can potentially execute code with elevated privileges or affect other users' sessions. Attack vector is network-based and likely requires low or no authentication depending on which form fields are affected. Once injected, the malicious script persists and executes in the browsers of any user who accesses the affected page, potentially enabling session hijacking, credential theft, or account compromise. Patch availability should be confirmed through Adobe's official security bulletin.

Affected products

  • Adobe Commerce <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats