Impact
Adobe Commerce is affected by a stored Cross‑Site Scripting vulnerability that allows a low‑privileged attacker to inject malicious JavaScript into form fields stored on the server. When a victim subsequently browses a page containing that field, the injected script runs in the victim's browser, potentially hijacking the session or granting the attacker elevated access. The CVE notes that scope is changed, meaning the attacker can perform actions beyond their original privileges.
Affected Systems
The affected products are Adobe Commerce, Adobe Commerce B2B and Magento Open Source. The CVE does not specify which versions are impacted, so administrators should review the Adobe security advisory APSB26‑92 for their particular installation.
Risk and Exploitability
The CVSS base score of 8.7 denotes high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The known CWE is 79. The likely attack vector involves a form‑based injection where the attacker stores malicious code that is later rendered to other authenticated users’ browsers, potentially enabling session hijacking or elevated account access.
OpenCVE Enrichment