Impact
Adobe Commerce is impacted by a stored Cross‑Site Scripting vulnerability that allows a high‑privileged attacker to inject form fields. When a privileged user submits a value containing script code, the data is stored and later rendered unchanged on a page that other users visit, resulting in execution of the malicious payload in the victim’s browser. Because the scope is altered, the attacker can affect both vendor‑specific and user‑specific domains.
Affected Systems
CVE‑2026‑47999 compromises Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. Exact version should consult Adobe’s Release Notes or the provided advisory link for details on affected releases and apply the recommended update accordingly. The vulnerability exists across form fields in each of these products.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity, while the EPSS score of 7% implies a non‑negligible likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would benefit from pre‑existing high‑privilege access required to submit form data. No public exploit has been reported, so the risk is primarily client‑side compromise—malicious scripts executed in victims’ browsers.
OpenCVE Enrichment