Description
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Published: 2026-08-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Adobe Commerce is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into form fields stored on the server. When a victim subsequently browses a page containing that field, the injected script runs in the victim's browser, potentially hijacking the session or granting the attacker elevated access. The CVE notes that scope is changed, meaning the attacker can perform actions beyond their original privileges.

Affected Systems

The affected products are Adobe Commerce, Adobe Commerce B2B and Magento Open Source. The CVE does not specify which versions are impacted, so administrators should review the Adobe security advisory APSB26‑92 for their particular installation.

Risk and Exploitability

The CVSS base score of 8.7 denotes high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The known CWE is 79. The likely attack vector involves a form‑based injection where the attacker stores malicious code that is later rendered to other authenticated users’ browsers, potentially enabling session hijacking or elevated account access.

Generated by OpenCVE AI on August 12, 2026 at 20:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Adobe security patch contained in the APSB26‑92 advisory.
  • Sanitize all form inputs on the server side to strip disallowed HTML or script content before storage.
  • Deploy a strict Content Security Policy that disallows inline scripts and limits script sources to prevent execution of injected code.

Generated by OpenCVE AI on August 12, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source
Vendors & Products Adobe
Adobe adobe Commerce
Adobe adobe Commerce B2b
Adobe magento Open Source

Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Title Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Adobe Adobe Commerce Adobe Commerce B2b Magento Open Source
cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published:

Updated: 2026-08-27T22:33:59.156Z

Reserved: 2026-05-21T15:28:38.144Z

Link: CVE-2026-48413

cve-icon Vulnrichment

Updated: 2026-08-12T16:10:38.772Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T18:17:31.150

Modified: 2026-08-28T00:17:58.697

Link: CVE-2026-48413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T21:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')