CVE-2026-21290 Details
Description
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
A stored Cross-Site Scripting (XSS) vulnerability has been identified in Adobe Commerce and Magento Open Source. This issue affects several versions, including Adobe Commerce 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier, as well as Magento Open Source 2.4.9-alpha3, 2.4.8-p3 and earlier, 2.4.7-p8 and earlier, 2.4.6-p13 and earlier, and 2.4.5-p15 and earlier. The vulnerability allows low-privileged attackers to inject malicious scripts into form fields, which could then be executed in the browsers of users who visit the affected page. This exploitation could lead to session takeover, significantly increasing the risks to confidentiality and integrity.
Users are advised to update to Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, or 2.4.4-p17. For Magento Open Source, users should update to 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, or 2.4.5-p16.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/magento/apsb26-05.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe commerce b2b | < 1.3.3 1.3.3 - 1.3.3 p1 1.3.3 p10 1.3.3 p11 1.3.3 p12 1.3.3 p13 1.3.3 p14 1.3.3 p15 1.3.3 p16 1.3.3 p2 1.3.3 p3 1.3.3 p4 1.3.3 p5 1.3.3 p6 1.3.3 p7 1.3.3 p8 1.3.3 p9 1.3.4 - 1.3.4 p1 1.3.4 p10 1.3.4 p11 1.3.4 p12 1.3.4 p13 1.3.4 p14 1.3.4 p15 1.3.4 p2 1.3.4 p3 1.3.4 p4 1.3.4 p5 1.3.4 p6 1.3.4 p7 1.3.4 p8 1.3.4 p9 1.3.5 - 1.3.5 p1 1.3.5 p10 1.3.5 p11 1.3.5 p12 1.3.5 p13 1.3.5 p2 1.3.5 p3 1.3.5 p4 1.3.5 p5 1.3.5 p6 1.3.5 p7 1.3.5 p8 1.3.5 p9 1.4.2 - 1.4.2 p1 1.4.2 p2 1.4.2 p3 1.4.2 p4 1.4.2 p5 1.4.2 p6 1.4.2 p7 1.4.2 p8 1.5.2 - 1.5.2 p1 1.5.2 p2 1.5.2 p3 1.5.3 alpha1 1.5.3 alpha2 1.5.3 alpha3 |
CPE
Remediation
| |
| adobe commerce | < 2.4.4 2.4.4 - 2.4.4 p1 2.4.4 p10 2.4.4 p11 2.4.4 p12 2.4.4 p13 2.4.4 p14 2.4.4 p15 2.4.4 p16 2.4.4 p2 2.4.4 p3 2.4.4 p4 2.4.4 p5 2.4.4 p6 2.4.4 p7 2.4.4 p8 2.4.4 p9 2.4.5 - 2.4.5 p1 2.4.5 p10 2.4.5 p11 2.4.5 p12 2.4.5 p13 2.4.5 p14 2.4.5 p15 2.4.5 p2 2.4.5 p3 2.4.5 p4 2.4.5 p5 2.4.5 p6 2.4.5 p7 2.4.5 p8 2.4.5 p9 2.4.6 - 2.4.6 p1 2.4.6 p10 2.4.6 p11 2.4.6 p12 2.4.6 p13 2.4.6 p2 2.4.6 p3 2.4.6 p4 2.4.6 p5 2.4.6 p6 2.4.6 p7 2.4.6 p8 2.4.6 p9 2.4.7 - 2.4.7 b1 2.4.7 b2 2.4.7 beta3 2.4.7 p1 2.4.7 p2 2.4.7 p3 2.4.7 p4 2.4.7 p5 2.4.7 p6 2.4.7 p7 2.4.7 p8 2.4.8 - 2.4.8 beta1 2.4.8 beta2 2.4.8 p1 2.4.8 p2 2.4.8 p3 2.4.9 alpha1 2.4.9 alpha2 2.4.9 alpha3 |
CPE
Remediation
| |
| adobe magento | < 2.4.5 2.4.5 - 2.4.5 p1 2.4.5 p10 2.4.5 p11 2.4.5 p12 2.4.5 p13 2.4.5 p14 2.4.5 p15 2.4.5 p2 2.4.5 p3 2.4.5 p4 2.4.5 p5 2.4.5 p6 2.4.5 p7 2.4.5 p8 2.4.5 p9 2.4.6 - 2.4.6 p1 2.4.6 p10 2.4.6 p11 2.4.6 p12 2.4.6 p13 2.4.6 p2 2.4.6 p3 2.4.6 p4 2.4.6 p5 2.4.6 p6 2.4.6 p7 2.4.6 p8 2.4.6 p9 2.4.7 - 2.4.7 b1 2.4.7 b2 2.4.7 beta3 2.4.7 p1 2.4.7 p2 2.4.7 p3 2.4.7 p4 2.4.7 p5 2.4.7 p6 2.4.7 p7 2.4.7 p8 2.4.8 - 2.4.8 beta1 2.4.8 beta2 2.4.8 p1 2.4.8 p2 2.4.8 p3 2.4.9 alpha3 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | CVE Modified | [email protected] |
| Aug 27, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Reanalysis | [email protected] |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 11, 2026 | New CVE Received | [email protected] |